CVE-2024-3096
- EPSS 1.07%
- Veröffentlicht 29.04.2024 04:15:08
- Zuletzt bearbeitet 04.11.2025 18:16:30
In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.
CVE-2022-48655
- EPSS 0.05%
- Veröffentlicht 28.04.2024 13:15:07
- Zuletzt bearbeitet 10.01.2025 19:06:09
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface...
CVE-2024-26928
- EPSS 0.02%
- Veröffentlicht 28.04.2024 12:15:21
- Zuletzt bearbeitet 01.12.2025 15:16:20
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_debug_files_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
CVE-2024-26923
- EPSS 0.01%
- Veröffentlicht 25.04.2024 06:15:57
- Zuletzt bearbeitet 23.12.2025 19:08:35
In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix garbage collector racing against connect() Garbage collector does not take into account the risk of embryo getting enqueued during the garbage collection. If such embr...
CVE-2024-26924
- EPSS 0.17%
- Veröffentlicht 25.04.2024 06:15:57
- Zuletzt bearbeitet 04.11.2025 18:15:55
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: do not free live element Pablo reports a crash with large batches of elements with a back-to-back add/remove pattern. Quoting Pablo: add_elem("000000...
CVE-2024-26925
- EPSS 0.01%
- Veröffentlicht 25.04.2024 06:15:57
- Zuletzt bearbeitet 23.12.2025 19:10:58
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path The commit mutex should not be released during the critical section between nft_gc_seq_begin() and nft_gc_s...
CVE-2024-26926
- EPSS 0.12%
- Veröffentlicht 25.04.2024 06:15:57
- Zuletzt bearbeitet 23.12.2025 18:53:47
In the Linux kernel, the following vulnerability has been resolved: binder: check offset alignment in binder_get_object() Commit 6d98eb95b450 ("binder: avoid potential data leakage when copying txn") introduced changes to how binder objects are cop...
CVE-2024-28130
- EPSS 0.12%
- Veröffentlicht 23.04.2024 15:15:49
- Zuletzt bearbeitet 04.11.2025 18:16:17
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to t...
CVE-2024-26922
- EPSS 0.02%
- Veröffentlicht 23.04.2024 13:15:46
- Zuletzt bearbeitet 23.12.2025 19:08:24
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping operations more clearly Verify the parameters of amdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.
CVE-2024-26917
- EPSS 0.01%
- Veröffentlicht 17.04.2024 16:15:08
- Zuletzt bearbeitet 03.02.2025 16:18:26
In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock" This reverts commit 1a1975551943f681772720f639ff42fbaa746212. This commit causes interrupts to be lost for FCo...