Latest CVE Feed
-
7.0
HIGHCVE-2024-50036
In the Linux kernel, the following vulnerability has been resolved: net: do not delay dst_entries_add() in dst_release() dst_entries_add() uses per-cpu data that might be freed at netns dismantle from ip6_route_net_exit() calling dst_entries_destroy() ... Read more
- Published: Oct. 21, 2024
- Modified: Nov. 17, 2024
-
7.8
HIGHCVE-2024-49991
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer Pass pointer reference to amdgpu_bo_unref to clear the correct pointer, otherwise amdgpu_bo_unref clear the local variable, the... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Nov. 17, 2024
-
7.8
HIGHCVE-2024-49986
In the Linux kernel, the following vulnerability has been resolved: platform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors x86_android_tablet_remove() frees the pdevs[] array, so it should not be used after calling x8... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Nov. 17, 2024
-
5.5
MEDIUMCVE-2024-47674
In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in error case As Jann points out, PFN mappings are special, because unlike normal memory mappings, there is no lifetime information associa... Read more
Affected Products : linux_kernel- Published: Oct. 15, 2024
- Modified: Nov. 17, 2024
-
7.8
HIGHCVE-2024-49509
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
5.5
MEDIUMCVE-2024-49510
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
5.5
MEDIUMCVE-2024-49511
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
5.5
MEDIUMCVE-2024-49512
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.8
HIGHCVE-2024-49508
InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.8
HIGHCVE-2024-49507
InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
8.1
HIGHCVE-2024-45670
IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.... Read more
Affected Products : soar- Published: Nov. 14, 2024
- Modified: Nov. 16, 2024
-
5.3
MEDIUMCVE-2024-45642
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr... Read more
- Published: Nov. 14, 2024
- Modified: Nov. 16, 2024
-
4.8
MEDIUMCVE-2024-45099
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr... Read more
- Published: Nov. 14, 2024
- Modified: Nov. 16, 2024
-
7.8
HIGHCVE-2024-49027
Microsoft Excel Remote Code Execution Vulnerability... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.8
HIGHCVE-2024-49026
Microsoft Excel Remote Code Execution Vulnerability... Read more
Affected Products : office 365_apps excel office_online_server office_long_term_servicing_channel office_2024 office_2021 office_2019- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.8
HIGHCVE-2024-49030
Microsoft Excel Remote Code Execution Vulnerability... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.8
HIGHCVE-2024-49029
Microsoft Excel Remote Code Execution Vulnerability... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.5
HIGHCVE-2024-49033
Microsoft Word Security Feature Bypass Vulnerability... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.5
HIGHCVE-2024-49040
Microsoft Exchange Server Spoofing Vulnerability... Read more
Affected Products : exchange_server- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
6.7
MEDIUM- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024