Categoria: CVE

CVE-2024-51132 | HAPI FHIR up to 6.3.x Request xml external entity reference

A vulnerability classified as problematic was found in HAPI FHIR up to 6.3.x. This vulnerability affects unknown code of the component Request Handler. The manipulation leads to xml external entity reference. This vulnerability was named CVE-2024-51132. Access to the local network is required for this attack to succeed. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-51362 | LSC Smart Connect Indoor IP Camera up to 7.6.32 RTSP Protocol information disclosure

A vulnerability classified as problematic has been found in LSC Smart Connect Indoor IP Camera up to 7.6.32. This affects an unknown part of the component RTSP Protocol Handler. The manipulation leads to information disclosure. This vulnerability is uniquely identified as CVE-2024-51362. It is possible to initiate the attack remotely. There is no exploit...

Per saperne di più

CVE-2024-50099 | Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4 Virtual Address simulate_ldr_literal Privilege Escalation

A vulnerability was found in Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4. It has been rated as problematic. Affected by this issue is the function simulate_ldr_literal of the component Virtual Address Handler. The manipulation leads to Privilege Escalation. This vulnerability is handled as CVE-2024-50099. The attack needs to be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-50128 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 Netlink Attribute lib/nlattr.c wwan_rtnl_policy out-of-bounds

A vulnerability was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. It has been declared as problematic. Affected by this vulnerability is the function wwan_rtnl_policy in the library lib/nlattr.c of the component Netlink Attribute Handler. The manipulation leads to out-of-bounds read. This vulnerability is known as CVE-2024-50128. It is possible to launch the attack on the physical device. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-50136 | Linux Kernel up to 6.1.114/6.6.58/6.11.5 mlx5 eswitch_vport_event information disclosure

A vulnerability was found in Linux Kernel up to 6.1.114/6.6.58/6.11.5. It has been classified as problematic. Affected is the function eswitch_vport_event of the component mlx5. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2024-50136. The attack can only be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-50097 | Linux Kernel up to 6.6.56/6.11.3/6.12-rc1 fec_ptp_init initialization (7745e14f4c03/3192e8d4a1ef/6be063071a45)

A vulnerability was found in Linux Kernel up to 6.6.56/6.11.3/6.12-rc1 and classified as problematic. This issue affects the function fec_ptp_init. The manipulation leads to improper initialization. The identification of this vulnerability is CVE-2024-50097. The attack can only be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-50135 | Linux Kernel up to 6.6.58/6.11.5 nvme-pci drivers/pci/msi/api.c nvme_dev_disable race condition (4ed32cc0939b/b33e49a5f254/26bc0a81f64c)

A vulnerability has been found in Linux Kernel up to 6.6.58/6.11.5 and classified as problematic. This vulnerability affects the function nvme_dev_disable of the file drivers/pci/msi/api.c of the component nvme-pci. The manipulation leads to race condition. This vulnerability was named CVE-2024-50135. The attack needs to be approached within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-50134 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 vboxvideo vbva_mouse_pointer_shape allocation of resources

A vulnerability, which was classified as problematic, was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. This affects the function vbva_mouse_pointer_shape of the component vboxvideo. The manipulation leads to allocation of resources. This vulnerability is uniquely identified as CVE-2024-50134. Access to the local network is required for this attack to succeed. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-50130 | Linux Kernel up to 6.6.58/6.11.5 netfilter __nf_unregister_net_hook use after free (f41bd93b3e05/d0d7939543a1/1230fe7ad397)

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.58/6.11.5. Affected by this issue is the function __nf_unregister_net_hook of the component netfilter. The manipulation leads to use after free. This vulnerability is handled as CVE-2024-50130. Access to the local network is required for this attack. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-50127 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 taprio_change use after free

A vulnerability classified as critical was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. Affected by this vulnerability is the function taprio_change. The manipulation leads to use after free. This vulnerability is known as CVE-2024-50127. The attack needs to be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-50093 | Linux Kernel up to 5.15.167/6.1.112/6.6.56/6.11.3 thermal drivers/pci/pci.c pcim_device_enable information disclosure

A vulnerability, which was classified as problematic, was found in Linux Kernel up to 5.15.167/6.1.112/6.6.56/6.11.3. Affected is the function pcim_device_enable of the file drivers/pci/pci.c of the component thermal. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2024-50093. The attack needs to be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-50090 | Linux Kernel up to 6.11.3 drm xe_bb_create_job buffer overflow (bcb5be342170/6c10ba06bb1b)

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.11.3. This issue affects the function xe_bb_create_job of the component drm. The manipulation leads to buffer overflow. The identification of this vulnerability is CVE-2024-50090. The attack can only be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più
Caricamento