CVE-2024-0408
- EPSS 0.02%
- Veröffentlicht 18.01.2024 16:15:08
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another r...
CVE-2024-0409
- EPSS 0.02%
- Veröffentlicht 18.01.2024 16:15:08
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX contex...
CVE-2024-0607
- EPSS 0.02%
- Veröffentlicht 18.01.2024 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:46:59
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of...
CVE-2024-0641
- EPSS 0.01%
- Veröffentlicht 17.01.2024 16:15:47
- Zuletzt bearbeitet 21.11.2024 08:47:03
A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system.
CVE-2024-0646
- EPSS 0.02%
- Veröffentlicht 17.01.2024 16:15:47
- Zuletzt bearbeitet 25.11.2024 10:44:03
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate thei...
CVE-2024-0639
- EPSS 0.01%
- Veröffentlicht 17.01.2024 16:15:46
- Zuletzt bearbeitet 21.11.2024 08:47:02
A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the syste...
CVE-2024-0232
- EPSS 0.02%
- Veröffentlicht 16.01.2024 14:15:48
- Zuletzt bearbeitet 21.11.2024 08:46:06
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a...
CVE-2024-0553
- EPSS 1.03%
- Veröffentlicht 16.01.2024 12:15:45
- Zuletzt bearbeitet 21.11.2024 08:46:51
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing s...
CVE-2024-0562
- EPSS 0.02%
- Veröffentlicht 15.01.2024 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:46:52
A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associated delayed work to complete. However, wb_inode_writeback_end() may schedule bandwidth estimation wo...
CVE-2023-4001
- EPSS 0.03%
- Veröffentlicht 15.01.2024 11:15:08
- Zuletzt bearbeitet 21.11.2024 08:34:11
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an exte...