CVE-2024-5629
- EPSS 0.07%
- Veröffentlicht 05.06.2024 15:15:12
- Zuletzt bearbeitet 21.11.2024 09:48:02
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
CVE-2024-5197
- EPSS 0.22%
- Veröffentlicht 03.06.2024 14:15:09
- Zuletzt bearbeitet 22.07.2025 18:17:56
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of t...
CVE-2024-36960
- EPSS 0.01%
- Veröffentlicht 03.06.2024 08:15:09
- Zuletzt bearbeitet 01.04.2025 18:36:15
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the drm_event to the size of the structure that's actually used. The length of the drm_event was...
CVE-2024-36954
- EPSS 0.02%
- Veröffentlicht 30.05.2024 16:15:18
- Zuletzt bearbeitet 14.01.2025 16:27:50
In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __skb_linearize() doesn't free the skb when it fails, so move '*buf = NULL' after __skb_linearize(), so that the skb can be freed on...
CVE-2024-36941
- EPSS 0.02%
- Veröffentlicht 30.05.2024 16:15:17
- Zuletzt bearbeitet 20.05.2025 15:16:04
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: don't free NULL coalescing rule If the parsing fails, we can dereference a NULL pointer here.
CVE-2024-36940
- EPSS 0.02%
- Veröffentlicht 30.05.2024 16:15:17
- Zuletzt bearbeitet 10.01.2025 18:29:29
In the Linux kernel, the following vulnerability has been resolved: pinctrl: core: delete incorrect free in pinctrl_enable() The "pctldev" struct is allocated in devm_pinctrl_register_and_init(). It's a devm_ managed pointer that is freed by devm_p...
CVE-2024-4453
- EPSS 2.3%
- Veröffentlicht 22.05.2024 20:15:09
- Zuletzt bearbeitet 17.12.2024 16:05:41
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit th...
CVE-2024-35973
- EPSS 0.01%
- Veröffentlicht 20.05.2024 10:15:12
- Zuletzt bearbeitet 04.04.2025 14:33:42
In the Linux kernel, the following vulnerability has been resolved: geneve: fix header validation in geneve[6]_xmit_skb syzbot is able to trigger an uninit-value in geneve_xmit() [1] Problem : While most ip tunnel helpers (like ip_tunnel_get_dsfie...
CVE-2024-35969
- EPSS 0.01%
- Veröffentlicht 20.05.2024 10:15:11
- Zuletzt bearbeitet 04.04.2025 14:45:29
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr Although ipv6_get_ifaddr walks inet6_addr_lst under the RCU lock, it still means hlist_for_each_entry_rcu can ret...
CVE-2024-35960
- EPSS 1.75%
- Veröffentlicht 20.05.2024 10:15:11
- Zuletzt bearbeitet 04.04.2025 14:22:45
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_rule_fg would only add newly created rules from the handle into the tree when they had a refcount of 1. On the ot...