CVE-2024-25714
- EPSS 0.16%
- Published 11.02.2024 03:15:09
- Last modified 21.11.2024 09:01:15
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which ...
CVE-2023-6356
- EPSS 0.03%
- Published 07.02.2024 21:15:08
- Last modified 21.11.2024 08:43:41
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and c...
CVE-2023-6536
- EPSS 0.03%
- Published 07.02.2024 21:15:08
- Last modified 21.11.2024 08:44:03
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, caus...
CVE-2024-24857
- EPSS 0.03%
- Published 05.02.2024 08:15:44
- Last modified 13.02.2025 18:17:10
A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.
CVE-2024-24858
- EPSS 0.02%
- Published 05.02.2024 08:15:44
- Last modified 13.02.2025 18:17:10
A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.
CVE-2024-1086
- EPSS 85.85%
- Published 31.01.2024 13:15:10
- Last modified 02.04.2025 20:32:33
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the n...
CVE-2023-46838
- EPSS 0.16%
- Published 29.01.2024 11:15:07
- Last modified 02.06.2025 19:15:21
Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be tra...
CVE-2024-0808
- EPSS 0.34%
- Published 24.01.2024 00:15:07
- Last modified 30.05.2025 15:15:31
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
CVE-2024-0741
- EPSS 47.68%
- Published 23.01.2024 14:15:38
- Last modified 30.05.2025 15:15:29
An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
CVE-2024-0742
- EPSS 0.75%
- Published 23.01.2024 14:15:38
- Last modified 30.05.2025 15:15:29
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and T...