CVE-2024-9676
- EPSS 1.33%
- Veröffentlicht 15.10.2024 16:15:06
- Zuletzt bearbeitet 19.03.2026 18:16:13
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image us...
CVE-2024-9675
- EPSS 0.14%
- Veröffentlicht 09.10.2024 15:15:17
- Zuletzt bearbeitet 25.08.2025 02:11:05
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/w...
CVE-2024-7006
- EPSS 0.62%
- Veröffentlicht 12.08.2024 13:38:40
- Zuletzt bearbeitet 03.11.2025 21:18:47
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentatio...
CVE-2024-6387
- EPSS 57.63%
- Veröffentlicht 01.07.2024 13:15:06
- Zuletzt bearbeitet 30.09.2025 13:52:23
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to aut...
CVE-2024-3049
- EPSS 1.03%
- Veröffentlicht 06.06.2024 06:15:09
- Zuletzt bearbeitet 02.10.2025 14:15:42
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
CVE-2023-3758
- EPSS 0.04%
- Veröffentlicht 18.04.2024 19:15:08
- Zuletzt bearbeitet 03.11.2025 21:15:59
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
CVE-2022-24809
- EPSS 0.14%
- Veröffentlicht 16.04.2024 20:15:09
- Zuletzt bearbeitet 17.01.2025 16:17:30
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Vers...
CVE-2022-24808
- EPSS 0.2%
- Veröffentlicht 16.04.2024 20:15:08
- Zuletzt bearbeitet 17.01.2025 16:16:28
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dere...
CVE-2022-24807
- EPSS 0.5%
- Veröffentlicht 16.04.2024 20:15:08
- Zuletzt bearbeitet 17.01.2025 16:15:01
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-writ...
CVE-2022-24806
- EPSS 0.21%
- Veröffentlicht 16.04.2024 20:15:08
- Zuletzt bearbeitet 17.01.2025 16:09:56
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subag...