|
303731
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: Check the validity of nr_words in bpf_iter_bits_new()
Check the validity of nr_words in bpf_iter_bits_new(). Without this
ch…
|
NVD-CWE-noinfo
|
CVE-2024-50253
|
2024-11-15 03:09 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303732
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mlxsw: spectrum_ipip: Fix memory leak when changing remote IPv6 address
The device stores IPv6 addresses that are used for encaps…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-50252
|
2024-11-15 03:08 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303733
|
5.3 |
MEDIUM
Network
|
sap
|
s\/4_hana
|
Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutabl…
|
CWE-650
Trusting HTTP Permission Methods on the Server Side
|
CVE-2024-45282
|
2024-11-15 02:56 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303734
|
4.3 |
MEDIUM
Network
|
sap
|
hana-client
|
The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. T…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2024-45277
|
2024-11-15 02:54 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303735
|
6.5 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence
|
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine host…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-37179
|
2024-11-15 02:35 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303736
|
5.4 |
MEDIUM
Network
|
sap
|
commerce_backoffice
|
SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45278
|
2024-11-15 02:17 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303737
|
4.8 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2024-36250
|
2024-11-15 02:11 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303738
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fsdax: dax_unshare_iter needs to copy entire blocks
The code that copies data from srcmap to iomap in dax_unshare_iter is
very ve…
|
NVD-CWE-noinfo
|
CVE-2024-50250
|
2024-11-15 02:04 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303739
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ACPI: CPPC: Make rmw_lock a raw_spin_lock
The following BUG was triggered:
=============================
[ BUG: Invalid wait con…
|
NVD-CWE-noinfo
|
CVE-2024-50249
|
2024-11-15 02:01 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303740
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
phy: qcom: qmp-usb-legacy: fix NULL-deref on runtime suspend
Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisati…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50239
|
2024-11-15 01:59 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|