|
304341
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: pse-pd: Fix out of bound for loop
Adjust the loop limit to prevent out-of-bounds access when iterating over
PI structures. T…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-50129
|
2024-11-8 06:49 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304342
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tracing/probes: Fix MAX_TRACE_ARGS limit handling
When creating a trace_probe we would set nr_args prior to truncating the
argume…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50132
|
2024-11-8 06:32 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304343
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Don't crash in stack_top() for tasks without vDSO
Not all tasks have a vDSO mapped, for example kthreads never do. If …
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50133
|
2024-11-8 06:17 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304344
|
5.4 |
MEDIUM
Network
|
basticom
|
framework
|
The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due to insufficient input sanitization and ou…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9443
|
2024-11-8 05:56 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304345
|
- |
|
-
|
-
|
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.
|
-
|
CVE-2024-51358
|
2024-11-8 05:35 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304346
|
4.3 |
MEDIUM
Network
|
shaon
|
post_from_frontend
|
The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack
|
CWE-352
Origin Validation Error
|
CVE-2024-9689
|
2024-11-8 05:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304347
|
- |
|
-
|
-
|
util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.
|
-
|
CVE-2024-47855
|
2024-11-8 05:35 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304348
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Vulnerability of processes not being fully terminated in the VPN module
Impact: Successful exploitation of this vulnerability will affect power consumption.
|
NVD-CWE-noinfo
|
CVE-2024-51513
|
2024-11-8 05:30 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304349
|
6.5 |
MEDIUM
Network
|
qualcomm
|
wsa8845h_firmware wsa8845_firmware wsa8840_firmware wsa8835_firmware wsa8832_firmware wsa8830_firmware wcn7881_firmware wcn7880_firmware wcn7861_firmware wcn7860_firmware
|
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
|
CWE-416
Use After Free
|
CVE-2024-33068
|
2024-11-8 05:07 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304350
|
6.5 |
MEDIUM
Network
|
qualcomm
|
wsa8845h_firmware wsa8845_firmware wsa8840_firmware wsa8835_firmware wsa8832_firmware wsa8830_firmware wcn7881_firmware wcn7880_firmware wcn7861_firmware wcn7860_firmware
|
Transient DOS while processing the CU information from RNR IE.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-38405
|
2024-11-8 05:06 |
2024-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|