CVE-2024-25711
- EPSS 4.08%
- Veröffentlicht 27.02.2024 02:15:06
- Zuletzt bearbeitet 04.11.2025 19:17:00
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is truste...
CVE-2024-23839
- EPSS 0.21%
- Veröffentlicht 26.02.2024 16:27:58
- Zuletzt bearbeitet 19.12.2024 19:38:28
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.respo...
CVE-2024-24568
- EPSS 0.06%
- Veröffentlicht 26.02.2024 16:27:58
- Zuletzt bearbeitet 19.12.2024 19:30:33
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3...
CVE-2024-25081
- EPSS 0.04%
- Veröffentlicht 26.02.2024 16:27:58
- Zuletzt bearbeitet 04.11.2025 19:16:58
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
CVE-2024-25082
- EPSS 0.91%
- Veröffentlicht 26.02.2024 16:27:58
- Zuletzt bearbeitet 04.11.2025 19:16:58
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
CVE-2024-23835
- EPSS 0.19%
- Veröffentlicht 26.02.2024 16:27:57
- Zuletzt bearbeitet 18.12.2024 18:07:03
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched...
CVE-2024-23836
- EPSS 0.85%
- Veröffentlicht 26.02.2024 16:27:57
- Zuletzt bearbeitet 19.12.2024 19:26:20
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft traffic to cause Suricata to use far more CPU and memory for processing th...
CVE-2024-23837
- EPSS 0.28%
- Veröffentlicht 26.02.2024 16:27:57
- Zuletzt bearbeitet 03.11.2025 19:15:43
LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.
CVE-2024-1622
- EPSS 0.2%
- Veröffentlicht 26.02.2024 16:27:52
- Zuletzt bearbeitet 27.02.2025 03:05:58
Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.
CVE-2024-21501
- EPSS 1.34%
- Veröffentlicht 24.02.2024 05:15:44
- Zuletzt bearbeitet 25.04.2025 19:37:25
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could ...