CVE-2024-50074
- EPSS 0.02%
- Veröffentlicht 29.10.2024 01:15:04
- Zuletzt bearbeitet 03.11.2025 23:16:47
In the Linux kernel, the following vulnerability has been resolved: parport: Proper fix for array out-of-bounds access The recent fix for array out-of-bounds accesses replaced sprintf() calls blindly with snprintf(). However, since snprintf() retu...
CVE-2024-9676
- EPSS 1.33%
- Veröffentlicht 15.10.2024 16:15:06
- Zuletzt bearbeitet 03.04.2025 02:15:19
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image us...
CVE-2024-9675
- EPSS 0.13%
- Veröffentlicht 09.10.2024 15:15:17
- Zuletzt bearbeitet 25.08.2025 02:11:05
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/w...
CVE-2024-9341
- EPSS 0.97%
- Veröffentlicht 01.10.2024 19:15:09
- Zuletzt bearbeitet 11.12.2024 04:15:06
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and tri...
CVE-2024-8354
- EPSS 0.04%
- Veröffentlicht 19.09.2024 11:15:10
- Zuletzt bearbeitet 21.11.2024 09:53:05
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the h...
CVE-2024-8443
- EPSS 0.16%
- Veröffentlicht 10.09.2024 14:15:13
- Zuletzt bearbeitet 03.11.2025 23:17:32
A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound ri...
CVE-2024-45617
- EPSS 0.12%
- Veröffentlicht 03.09.2024 22:15:05
- Zuletzt bearbeitet 03.11.2025 23:15:51
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing che...
CVE-2024-45618
- EPSS 0.09%
- Veröffentlicht 03.09.2024 22:15:05
- Zuletzt bearbeitet 03.11.2025 23:15:51
A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions ...
CVE-2024-45619
- EPSS 0.07%
- Veröffentlicht 03.09.2024 22:15:05
- Zuletzt bearbeitet 03.11.2025 23:15:52
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially fi...
CVE-2024-45620
- EPSS 0.07%
- Veröffentlicht 03.09.2024 22:15:05
- Zuletzt bearbeitet 03.11.2025 23:15:52
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized...