CVE-2022-24806
- EPSS 0.14%
- Published 16.04.2024 20:15:08
- Last modified 17.01.2025 16:09:56
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subag...
CVE-2022-24807
- EPSS 0.5%
- Published 16.04.2024 20:15:08
- Last modified 17.01.2025 16:15:01
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-writ...
CVE-2022-24808
- EPSS 0.2%
- Published 16.04.2024 20:15:08
- Last modified 17.01.2025 16:16:28
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dere...
CVE-2022-24805
- EPSS 0.48%
- Published 16.04.2024 20:15:07
- Last modified 17.01.2025 16:04:56
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read...
CVE-2024-3567
- EPSS 0.09%
- Published 10.04.2024 15:16:05
- Last modified 06.05.2025 09:15:17
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and ca...
CVE-2024-1394
- EPSS 1.02%
- Published 21.03.2024 13:00:08
- Last modified 13.05.2025 09:15:19
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. Th...
CVE-2024-2496
- EPSS 0.03%
- Published 18.03.2024 13:15:08
- Last modified 09.04.2025 15:36:43
A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. Th...
CVE-2024-2002
- EPSS 0.11%
- Published 18.03.2024 13:15:07
- Last modified 09.04.2025 15:36:37
A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results.
CVE-2023-7250
- EPSS 0.04%
- Published 18.03.2024 13:15:06
- Last modified 07.04.2025 16:57:33
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely wa...
CVE-2023-6917
- EPSS 0.02%
- Published 28.02.2024 15:15:07
- Last modified 01.04.2025 15:34:51
A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group pri...