|
256271
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: validate vlan header
Ensure there is sufficient room to access the protocol field of the
VLAN header, valid…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-44983
|
2024-09-11 01:57 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256272
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Free job before xe_exec_queue_put
Free job depends on job->vm being valid, the last xe_exec_queue_put can
destroy the VM.…
|
CWE-416
Use After Free
|
CVE-2024-44978
|
2024-09-11 01:51 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256273
|
8.6 |
HIGH
Network
|
fogproject
|
fogproject
|
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 an…
|
CWE-77
Command Injection
|
CVE-2024-42348
|
2024-09-11 01:49 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256274
|
5.3 |
MEDIUM
Network
|
fogproject
|
fogproject
|
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via logs stored directly on the root of the web server. F…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-42349
|
2024-09-11 01:44 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256275
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verifi…
|
NVD-CWE-Other
|
CVE-2024-38886
|
2024-09-11 01:40 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256276
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of s…
|
CWE-89
SQL Injection
|
CVE-2024-38889
|
2024-09-11 01:38 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256277
|
- |
|
-
|
-
|
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
|
-
|
CVE-2023-37226
|
2024-09-11 01:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256278
|
- |
|
-
|
-
|
An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.
|
-
|
CVE-2024-42759
|
2024-09-11 01:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256279
|
- |
|
-
|
-
|
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook r…
|
-
|
CVE-2024-45393
|
2024-09-11 00:50 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256280
|
- |
|
-
|
-
|
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes a command in bconsole using an abbreviation (i.e. …
|
CWE-285
Improper Authorization
|
CVE-2024-45044
|
2024-09-11 00:50 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|