CVE-2024-27401
- EPSS 0.01%
- Veröffentlicht 14.05.2024 15:12:29
- Zuletzt bearbeitet 22.01.2026 20:39:28
In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into account when fetching packet contents Ensure that packet_buffer_get respects the user_length provided. If the length of the head pa...
CVE-2024-27398
- EPSS 0.67%
- Veröffentlicht 14.05.2024 15:12:28
- Zuletzt bearbeitet 22.01.2026 20:37:07
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge ...
CVE-2024-27399
- EPSS 0.01%
- Veröffentlicht 14.05.2024 15:12:28
- Zuletzt bearbeitet 22.01.2026 20:37:12
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the c...
CVE-2024-25641
- EPSS 88.31%
- Veröffentlicht 14.05.2024 15:05:50
- Zuletzt bearbeitet 04.11.2025 17:15:46
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permis...
CVE-2024-4558
- EPSS 2.58%
- Veröffentlicht 07.05.2024 19:15:08
- Zuletzt bearbeitet 04.11.2025 18:16:42
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-4559
- EPSS 0.33%
- Veröffentlicht 07.05.2024 19:15:08
- Zuletzt bearbeitet 19.12.2024 20:47:26
Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-34397
- EPSS 0.19%
- Veröffentlicht 07.05.2024 18:15:08
- Zuletzt bearbeitet 04.11.2025 22:16:01
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can ...
CVE-2024-34064
- EPSS 1.15%
- Veröffentlicht 06.05.2024 15:15:23
- Zuletzt bearbeitet 03.11.2025 22:16:54
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting ...
CVE-2024-34069
- EPSS 41.94%
- Veröffentlicht 06.05.2024 15:15:23
- Zuletzt bearbeitet 03.12.2025 15:32:11
Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to intera...
CVE-2024-34500
- EPSS 0.3%
- Veröffentlicht 05.05.2024 19:15:07
- Zuletzt bearbeitet 04.11.2025 18:16:22
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to ...