CVE-2024-0639
- EPSS 0.01%
- Veröffentlicht 17.01.2024 16:15:46
- Zuletzt bearbeitet 21.11.2024 08:47:02
A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the syste...
CVE-2024-0232
- EPSS 0.02%
- Veröffentlicht 16.01.2024 14:15:48
- Zuletzt bearbeitet 21.11.2024 08:46:06
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a...
CVE-2024-0553
- EPSS 1.03%
- Veröffentlicht 16.01.2024 12:15:45
- Zuletzt bearbeitet 21.11.2024 08:46:51
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing s...
CVE-2024-0562
- EPSS 0.02%
- Veröffentlicht 15.01.2024 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:46:52
A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associated delayed work to complete. However, wb_inode_writeback_end() may schedule bandwidth estimation wo...
CVE-2023-4001
- EPSS 0.04%
- Veröffentlicht 15.01.2024 11:15:08
- Zuletzt bearbeitet 21.11.2024 08:34:11
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an exte...
CVE-2023-6915
- EPSS 0.01%
- Veröffentlicht 15.01.2024 10:15:26
- Zuletzt bearbeitet 21.11.2024 08:44:49
A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return.
CVE-2024-23301
- EPSS 0.1%
- Veröffentlicht 12.01.2024 23:15:10
- Zuletzt bearbeitet 10.12.2025 17:15:50
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
CVE-2023-6683
- EPSS 0.07%
- Veröffentlicht 12.01.2024 19:15:11
- Zuletzt bearbeitet 02.05.2025 15:10:54
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading t...
CVE-2024-0443
- EPSS 0.01%
- Veröffentlicht 12.01.2024 00:15:45
- Zuletzt bearbeitet 21.11.2024 08:46:36
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is calle...
CVE-2023-5455
- EPSS 0.3%
- Veröffentlicht 10.01.2024 13:15:48
- Zuletzt bearbeitet 21.11.2024 08:41:47
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of ...