CVE-2024-26937
- EPSS 0.01%
- Veröffentlicht 01.05.2024 06:15:08
- Zuletzt bearbeitet 23.12.2025 18:55:15
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Reset queue_priority_hint on parking Originally, with strict in order execution, we could complete execution only when the queue was empty. Preempt-to-busy allows repl...
CVE-2024-26931
- EPSS 0.01%
- Veröffentlicht 01.05.2024 06:15:07
- Zuletzt bearbeitet 03.03.2025 17:47:59
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix command flush on cable pull System crash due to command failed to flush back to SCSI layer. BUG: unable to handle kernel NULL pointer dereference at 0000000000...
CVE-2024-3096
- EPSS 1.07%
- Veröffentlicht 29.04.2024 04:15:08
- Zuletzt bearbeitet 04.11.2025 18:16:30
In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.
CVE-2022-48655
- EPSS 0.05%
- Veröffentlicht 28.04.2024 13:15:07
- Zuletzt bearbeitet 10.01.2025 19:06:09
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface...
CVE-2024-26928
- EPSS 0.02%
- Veröffentlicht 28.04.2024 12:15:21
- Zuletzt bearbeitet 01.12.2025 15:16:20
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_debug_files_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.
CVE-2024-26923
- EPSS 0.01%
- Veröffentlicht 25.04.2024 06:15:57
- Zuletzt bearbeitet 23.12.2025 19:08:35
In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix garbage collector racing against connect() Garbage collector does not take into account the risk of embryo getting enqueued during the garbage collection. If such embr...
CVE-2024-26924
- EPSS 0.17%
- Veröffentlicht 25.04.2024 06:15:57
- Zuletzt bearbeitet 04.11.2025 18:15:55
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: do not free live element Pablo reports a crash with large batches of elements with a back-to-back add/remove pattern. Quoting Pablo: add_elem("000000...
CVE-2024-26925
- EPSS 0.01%
- Veröffentlicht 25.04.2024 06:15:57
- Zuletzt bearbeitet 23.12.2025 19:10:58
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path The commit mutex should not be released during the critical section between nft_gc_seq_begin() and nft_gc_s...
CVE-2024-26926
- EPSS 0.16%
- Veröffentlicht 25.04.2024 06:15:57
- Zuletzt bearbeitet 23.12.2025 18:53:47
In the Linux kernel, the following vulnerability has been resolved: binder: check offset alignment in binder_get_object() Commit 6d98eb95b450 ("binder: avoid potential data leakage when copying txn") introduced changes to how binder objects are cop...
CVE-2024-28130
- EPSS 0.12%
- Veröffentlicht 23.04.2024 15:15:49
- Zuletzt bearbeitet 04.11.2025 18:16:17
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to t...