CVE-2024-28757
- EPSS 0.64%
- Published 10.03.2024 05:15:06
- Last modified 28.03.2025 19:15:21
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
CVE-2023-52585
- EPSS 0.01%
- Published 06.03.2024 07:15:07
- Last modified 14.03.2025 18:57:42
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper() Return invalid error code -EINVAL for invalid block id. Fixes the below: drivers/gpu/drm/amd/a...
CVE-2024-26462
- EPSS 0.02%
- Published 29.02.2024 01:44:18
- Last modified 25.03.2025 20:15:21
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
CVE-2024-26461
- EPSS 0.08%
- Published 29.02.2024 01:44:18
- Last modified 23.05.2025 15:30:30
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
CVE-2024-26458
- EPSS 0.21%
- Published 29.02.2024 01:44:18
- Last modified 23.05.2025 15:39:31
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
CVE-2022-36879
- EPSS 0.04%
- Published 27.07.2022 04:15:10
- Last modified 05.05.2025 16:15:17
An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.
- EPSS 25.23%
- Published 21.06.2022 15:15:09
- Last modified 15.09.2025 14:15:33
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022...
CVE-2022-0995
- EPSS 22.29%
- Published 25.03.2022 19:15:10
- Last modified 21.11.2024 06:39:49
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of ser...
- EPSS 0.06%
- Published 03.03.2022 19:15:08
- Last modified 21.11.2024 06:21:58
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kerne...
CVE-2021-3772
- EPSS 0.16%
- Published 02.03.2022 23:15:09
- Last modified 21.11.2024 06:22:23
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP ad...