Latest CVE Feed
-
6.7
MEDIUMCVE-2024-49408
Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.... Read more
- Published: Nov. 06, 2024
- Modified: Nov. 13, 2024
-
6.7
MEDIUMCVE-2024-49409
Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.... Read more
- Published: Nov. 06, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-49952
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: prevent nf_skb_duplicated corruption syzbot found that nf_dup_ipv4() or nf_dup_ipv6() could write per-cpu variable nf_skb_duplicated in an unsafe way [1]. Disabli... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-50094
In the Linux kernel, the following vulnerability has been resolved: sfc: Don't invoke xdp_do_flush() from netpoll. Yury reported a crash in the sfc driver originated from netpoll_send_udp(). The netconsole sends a message and then netpoll invokes the dr... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 13, 2024
-
3.3
LOWCVE-2024-50092
In the Linux kernel, the following vulnerability has been resolved: net: netconsole: fix wrong warning A warning is triggered when there is insufficient space in the buffer for userdata. However, this is not an issue since userdata will be sent in the n... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-50091
In the Linux kernel, the following vulnerability has been resolved: dm vdo: don't refer to dedupe_context after releasing it Clear the dedupe_context pointer in a data_vio whenever ownership of the context is lost, so that vdo can't examine it accidenta... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 12, 2024
-
5.5
MEDIUMCVE-2024-49946
In the Linux kernel, the following vulnerability has been resolved: ppp: do not assume bh is held in ppp_channel_bridge_input() Networking receive path is usually handled from BH handler. However, some protocols need to acquire the socket lock, and pack... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Nov. 12, 2024
-
6.5
MEDIUMCVE-2023-45872
An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is not known yet, there is an assumption that it is an SVG document, leading to a denial of service (application crash) if ... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Nov. 12, 2024
-
5.5
MEDIUMCVE-2024-49947
In the Linux kernel, the following vulnerability has been resolved: net: test for not too small csum_start in virtio_net_hdr_to_skb() syzbot was able to trigger this warning [1], after injecting a malicious packet through af_packet, setting skb->csum_st... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Nov. 12, 2024
-
5.5
MEDIUMCVE-2024-49948
In the Linux kernel, the following vulnerability has been resolved: net: add more sanity checks to qdisc_pkt_len_init() One path takes care of SKB_GSO_DODGY, assuming skb->len is bigger than hdr_len. virtio_net_hdr_to_skb() does not fully dissect TCP h... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Nov. 12, 2024
-
5.5
MEDIUMCVE-2024-49949
In the Linux kernel, the following vulnerability has been resolved: net: avoid potential underflow in qdisc_pkt_len_init() with UFO After commit 7c6d2ecbda83 ("net: be more gentle about silly gso requests coming from user") virtio_net_hdr_to_skb() had s... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47636
Deserialization of Untrusted Data vulnerability in Eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.9.... Read more
- Published: Oct. 10, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-43929
Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.... Read more
Affected Products : jobsearch_wp_job_board- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-43928
Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.... Read more
Affected Products : jobsearch_wp_job_board- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47302
Missing Authorization vulnerability in WPManageNinja LLC Fluent Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through 1.8.0.... Read more
Affected Products : fluent_support- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47308
Missing Authorization vulnerability in Templately allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Templately: from n/a through 3.1.2.... Read more
Affected Products : templately- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47311
Missing Authorization vulnerability in Kraft Plugins Wheel of Life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through 1.1.8.... Read more
Affected Products : wheel_of_life- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-47314
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.8.... Read more
Affected Products : sunshine_photo_cart- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-47317
Missing Authorization vulnerability in WP Quads Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads: from n/a th... Read more
Affected Products : ads- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-47318
Missing Authorization vulnerability in Magazine3 PWA for WP & AMP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PWA for WP & AMP: from n/a through 1.7.72.... Read more
Affected Products : pwa_for_wp_\&_amp- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024