- EPSS 0.12%
- Veröffentlicht 16.04.2024 16:15:08
- Zuletzt bearbeitet 01.04.2025 14:32:41
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
CVE-2024-3864
- EPSS 0.98%
- Veröffentlicht 16.04.2024 16:15:08
- Zuletzt bearbeitet 01.04.2025 17:39:30
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects ...
CVE-2024-32487
- EPSS 0.33%
- Veröffentlicht 13.04.2024 15:15:52
- Zuletzt bearbeitet 17.06.2025 20:58:12
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untr...
CVE-2024-26817
- EPSS 0.2%
- Veröffentlicht 13.04.2024 12:15:11
- Zuletzt bearbeitet 04.11.2025 19:17:03
In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of doing the multiplication which might overflow.
CVE-2024-26816
- EPSS 0.02%
- Veröffentlicht 10.04.2024 14:15:07
- Zuletzt bearbeitet 12.05.2026 12:16:20
In the Linux kernel, the following vulnerability has been resolved: x86, relocs: Ignore relocations in .notes section When building with CONFIG_XEN_PV=y, .text symbols are emitted into the .notes section so that Xen can find the "startup_xen" entry...
CVE-2024-31309
- EPSS 10.85%
- Veröffentlicht 10.04.2024 12:15:09
- Zuletzt bearbeitet 04.11.2025 19:17:08
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config.http2.max_continuation_frames...
CVE-2024-26812
- EPSS 0.01%
- Veröffentlicht 05.04.2024 09:15:09
- Zuletzt bearbeitet 12.05.2026 12:16:20
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Create persistent INTx handler A vulnerability exists where the eventfd for INTx signaling can be deconfigured, which unregisters the IRQ handler but still allows eventfd...
CVE-2024-26814
- EPSS 0.02%
- Veröffentlicht 05.04.2024 09:15:09
- Zuletzt bearbeitet 27.03.2025 21:36:57
In the Linux kernel, the following vulnerability has been resolved: vfio/fsl-mc: Block calling interrupt handler without trigger The eventfd_ctx trigger pointer of the vfio_fsl_mc_irq object is initially NULL and may become NULL if the user sets th...
CVE-2024-27437
- EPSS 0.02%
- Veröffentlicht 05.04.2024 09:15:09
- Zuletzt bearbeitet 12.05.2026 12:16:33
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Disable auto-enable of exclusive INTx IRQ Currently for devices requiring masking at the irqchip for INTx, ie. devices without DisINTx support, the IRQ is enabled in requ...
CVE-2023-38709
- EPSS 3.91%
- Veröffentlicht 04.04.2024 20:15:08
- Zuletzt bearbeitet 04.11.2025 22:15:53
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.