CVE-2024-12426
- EPSS 0.13%
- Veröffentlicht 07.01.2025 13:15:07
- Zuletzt bearbeitet 08.12.2025 18:35:10
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values, so potentially s...
CVE-2024-12425
- EPSS 0.22%
- Veröffentlicht 07.01.2025 12:15:24
- Zuletzt bearbeitet 08.12.2025 18:38:59
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supp...
CVE-2024-46981
- EPSS 64.8%
- Veröffentlicht 06.01.2025 22:15:09
- Zuletzt bearbeitet 05.09.2025 14:20:13
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage collector and potentially lead to remote code execution. The problem is fixed in 7.4.2, 7.2.7, a...
CVE-2024-56705
- EPSS 0%
- Veröffentlicht 28.12.2024 10:15:19
- Zuletzt bearbeitet 15.12.2025 20:53:18
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Add check for rgby_data memory allocation failure In ia_css_3a_statistics_allocate(), there is no check on the allocation result of the rgby_data memory. If rgby_da...
CVE-2024-56644
- EPSS 0.01%
- Veröffentlicht 27.12.2024 15:15:24
- Zuletzt bearbeitet 12.01.2026 13:10:13
In the Linux kernel, the following vulnerability has been resolved: net/ipv6: release expired exception dst cached in socket Dst objects get leaked in ip6_negative_advice() when this function is executed for an expired IPv6 route located in the exc...
CVE-2024-53197
- EPSS 1.54%
- Veröffentlicht 27.12.2024 14:15:27
- Zuletzt bearbeitet 04.11.2025 16:47:12
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_ge...
CVE-2024-53150
- EPSS 1%
- Veröffentlicht 24.12.2024 12:15:23
- Zuletzt bearbeitet 04.11.2025 16:47:05
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. ...
CVE-2024-47606
- EPSS 0.21%
- Veröffentlicht 12.12.2024 02:03:32
- Zuletzt bearbeitet 03.11.2025 21:16:24
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs due to an underflow of the gint size variabl...
CVE-2024-46901
- EPSS 5.81%
- Veröffentlicht 09.12.2024 10:15:05
- Zuletzt bearbeitet 15.07.2025 16:35:39
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. ...
CVE-2024-53104
- EPSS 10.13%
- Veröffentlicht 02.12.2024 08:15:08
- Zuletzt bearbeitet 04.11.2025 14:36:37
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when c...