CVE-2024-2398
- EPSS 1.96%
- Published 27.03.2024 08:15:41
- Last modified 30.07.2025 19:42:27
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all...
CVE-2024-26641
- EPSS 0.02%
- Published 18.03.2024 11:15:11
- Last modified 28.03.2025 16:17:08
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and initialize...
CVE-2024-22259
- EPSS 30.51%
- Published 16.03.2024 05:15:20
- Last modified 10.06.2025 15:55:48
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.or...
CVE-2024-28757
- EPSS 0.64%
- Published 10.03.2024 05:15:06
- Last modified 28.03.2025 19:15:21
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
CVE-2024-26458
- EPSS 0.21%
- Published 29.02.2024 01:44:18
- Last modified 23.05.2025 15:39:31
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
CVE-2024-26461
- EPSS 0.08%
- Published 29.02.2024 01:44:18
- Last modified 23.05.2025 15:30:30
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
CVE-2024-26462
- EPSS 0.02%
- Published 29.02.2024 01:44:18
- Last modified 25.03.2025 20:15:21
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
CVE-2024-22201
- EPSS 0.45%
- Published 26.02.2024 16:27:56
- Last modified 13.02.2025 18:16:46
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file d...
CVE-2024-22243
- EPSS 48.23%
- Published 23.02.2024 05:15:08
- Last modified 13.02.2025 18:16:47
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/6...
CVE-2024-1635
- EPSS 8.33%
- Published 19.02.2024 22:15:48
- Last modified 07.05.2025 12:27:53
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immedia...