CVE-2024-0408
- EPSS 0.02%
- Veröffentlicht 18.01.2024 16:15:08
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another r...
CVE-2024-0409
- EPSS 0.02%
- Veröffentlicht 18.01.2024 16:15:08
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX contex...
CVE-2024-0607
- EPSS 0.02%
- Veröffentlicht 18.01.2024 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:46:59
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of...
CVE-2023-6816
- EPSS 3.08%
- Veröffentlicht 18.01.2024 05:15:08
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for th...
CVE-2024-0517
- EPSS 67.67%
- Veröffentlicht 16.01.2024 22:15:37
- Zuletzt bearbeitet 22.05.2025 18:15:33
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-0518
- EPSS 0.15%
- Veröffentlicht 16.01.2024 22:15:37
- Zuletzt bearbeitet 21.11.2024 08:46:46
Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-0519
- EPSS 0.42%
- Veröffentlicht 16.01.2024 22:15:37
- Zuletzt bearbeitet 24.10.2025 14:07:56
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6395
- EPSS 0.41%
- Veröffentlicht 16.01.2024 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:43:46
The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the ex...
CVE-2024-0232
- EPSS 0.02%
- Veröffentlicht 16.01.2024 14:15:48
- Zuletzt bearbeitet 21.11.2024 08:46:06
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a...
CVE-2024-0567
- EPSS 1.19%
- Veröffentlicht 16.01.2024 14:15:48
- Zuletzt bearbeitet 21.11.2024 08:46:53
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, r...