CVE-2024-46544
- EPSS 0.03%
- Veröffentlicht 23.09.2024 11:15:10
- Zuletzt bearbeitet 10.07.2025 19:11:29
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache ...
CVE-2024-8096
- EPSS 0.56%
- Veröffentlicht 11.09.2024 10:15:02
- Zuletzt bearbeitet 30.07.2025 19:42:16
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. ...
- EPSS 6.54%
- Veröffentlicht 15.08.2024 19:15:19
- Zuletzt bearbeitet 19.08.2025 15:21:28
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have acces...
CVE-2024-41073
- EPSS 0.02%
- Veröffentlicht 29.07.2024 15:15:15
- Zuletzt bearbeitet 14.01.2026 16:24:53
In the Linux kernel, the following vulnerability has been resolved: nvme: avoid double free special payload If a discard request needs to be retried, and that retry may fail before a new special payload is added, a double free will result. Clear th...
CVE-2024-41000
- EPSS 0.02%
- Veröffentlicht 12.07.2024 13:15:20
- Zuletzt bearbeitet 14.01.2026 16:22:44
In the Linux kernel, the following vulnerability has been resolved: block/ioctl: prefer different overflow check Running syzkaller with the newly reintroduced signed integer overflow sanitizer shows this report: [ 62.982337] ------------[ cut he...
CVE-2024-39494
- EPSS 0.01%
- Veröffentlicht 12.07.2024 13:15:12
- Zuletzt bearbeitet 06.01.2026 15:06:55
In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name ->d_name.name can change on rename and the earlier value can be freed; there are conditions sufficient to stabilize it (->d_lock on...
CVE-2024-39496
- EPSS 0.02%
- Veröffentlicht 12.07.2024 13:15:12
- Zuletzt bearbeitet 06.01.2026 15:07:04
In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix use-after-free due to race with dev replace While loading a zone's info during creation of a block group, we can race with a device replace operation and then tri...
CVE-2024-6387
- EPSS 25.87%
- Veröffentlicht 01.07.2024 13:15:06
- Zuletzt bearbeitet 30.09.2025 13:52:23
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to aut...
CVE-2024-37371
- EPSS 2.61%
- Veröffentlicht 28.06.2024 23:15:11
- Zuletzt bearbeitet 03.11.2025 21:16:13
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
CVE-2024-38588
- EPSS 0.01%
- Veröffentlicht 19.06.2024 14:15:18
- Zuletzt bearbeitet 23.12.2025 15:03:56
In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix possible use-after-free issue in ftrace_location() KASAN reports a bug: BUG: KASAN: use-after-free in ftrace_location+0x90/0x120 Read of size 8 at addr ffff888141d...