Search

Found 4,677 results in 637ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-52791 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: i2c: core: Run atomic i2c xfer when !preemptible Since bae1d3a05a8b, i2c transfers are non-atomic if preemption is disabled. Howe…
CVE-2023-52784 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: bonding: stop the device in bond_setup_by_slave() Commit 9eed321cde22 ("net: lapbether: only support ethernet devices") has been …
CVE-2023-52775 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid data corruption caused by decline We found a data corruption issue during testing of SMC-R on Redis applications. …
CVE-2023-52762 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: virtio-blk: fix implicit overflow on virtio_max_dma_size The following codes have an implicit conversion from size_t to u32: (u32…
CVE-2023-52756 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:5102: kernel-rt security update (Important)
CVE-2023-52730 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: mmc: sdio: fix possible resource leaks in some error paths If sdio_add_func() or sdio_init_func() fails, sdio_remove_func() can n…
CVE-2023-52703 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: net/usb: kalmia: Don't pass act_len in usb_bulk_msg error path syzbot reported that act_len in kalmia_send_init_packet() is unini…
CVE-2023-52686 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_event_init() kasprintf() returns a pointer to dynamically allocated memory whic…
CVE-2023-52683 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: ACPI: LPIT: Avoid u32 multiplication overflow In lpit_update_residency() there is a possibility of overflow in multiplication, if…
CVE-2023-52679 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: of: Fix double free in of_parse_phandle_with_args_map In of_parse_phandle_with_args_map() the inner loop that iterates through th…
CVE-2023-52662 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node When ida_alloc_max fails, resources allocated before should be freed, includi…
CVE-2023-52648 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Unmap the surface before resetting it on a plane state Switch to a new plane state requires unreferencing of all held…
CVE-2023-52622 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: avoid online resizing failures due to oversized flex bg When we online resize an ext4 filesystem with a oversized flexbg_si…
CVE-2023-52619 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: pstore/ram: Fix crash when setting number of cpus to an odd number When the number of cpu cores is adjusted to 7 or other odd num…
CVE-2023-52615 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in the hwrng device read path. This triggers when t…
CVE-2023-52614 high 7.8 7.8 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix buffer overflow in trans_stat_show Fix buffer overflow in trans_stat_show(). Convert simple snprintf to the mo…
CVE-2023-52560 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: mm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions() When CONFIG_DAMON_VADDR_KUNIT_TEST=y and making CONFI…
CVE-2023-52464 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: EDAC/thunderx: Fix possible out-of-bounds string access Enabling -Wstringop-overflow globally exposes a warning for a common bug …
CVE-2023-52451 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/memhp: Fix access beyond end of drmem array dlpar_memory_remove_by_index() may access beyond the bounds of the dr…
CVE-2023-42956 high 8.0 FIX rhel slesdebian debian 2y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service.
CVE-2023-42950 high 8.0 FIX rhel slesdebian debian 2y ago A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously …
CVE-2023-42843 high 8.0 FIX rhel slesdebian debian 2y ago An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visit…
CVE-2022-49675 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: tick/nohz: unexport __init-annotated tick_nohz_full_setup() EXPORT_SYMBOL and __init is a bad combination because the .init.text …
CVE-2022-49226 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: net: asix: add proper error handling of usb read errors Syzbot once again hit uninit value in asix driver. The problem still the …
CVE-2022-48804 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: vt_ioctl: fix array_index_nospec in vt_setactivate array_index_nospec ensures that an out-of-bounds value is set to zero on the t…
CVE-2021-47497 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells If a cell has 'nbits' equal to a multiple of BITS_PER_BYTE the logic …
CVE-2021-47495 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: usbnet: sanity check for maxpacket maxpacket of 0 makes no sense and oopses as we need to divide by it. Give up. V2: fixed typo …
CVE-2021-47432 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: lib/generic-radix-tree.c: Don't overflow in peek() When we started spreading new inode numbers throughout most of the 64 bit inod…
CVE-2021-47386 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field If driver read val value sufficient for (va…
CVE-2021-47384 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field If driver read tmp value sufficient for (tmp…
CVE-2021-47101 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: asix: fix uninit-value in asix_mdio_read() asix_read_cmd() may read less than sizeof(smsr) bytes and in this case smsr will be un…
CVE-2024-9407 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:8846: container-tools:rhel8 security update (Important)
CVE-2023-5841 high 8.0 FIX rhel sles rocky 2y ago Important: openexr security update
CVE-2024-47875 high 8.0 FIX rheldebian debian rocky 2y ago DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
CVE-2024-26961 high 7.8 7.8 FIX rhel rocky sles 2y ago Moderate: kernel security update
CVE-2024-9675 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:8846: container-tools:rhel8 security update (Important)
CVE-2025-43480 high 8.0 FIX rocky rhel sles 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrat…
CVE-2024-54534 high 8.0 FIX rhel slesdebian debian 2y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processi…
CVE-2024-4558 high 8.0 FIX rhel rockydebian debian 2y ago Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-44187 high 8.0 FIX rhel rocky sles 2y ago A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, …
CVE-2024-44185 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted we…
CVE-2024-40866 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiting a malicious website may lead to address bar spoofing.
CVE-2024-40789 high 8.0 FIX rhel rocky sles 2y ago An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, vi…
CVE-2024-40782 high 8.0 FIX rhel rocky sles 2y ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionO…
CVE-2024-40780 high 8.0 FIX rhel rocky sles 2y ago An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1…
CVE-2024-40779 high 8.0 FIX rhel rocky sles 2y ago An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1…
CVE-2024-40776 high 8.0 FIX rhel sles rocky 2y ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionO…
CVE-2024-39502 high 7.8 7.8 FIX rhel rocky sles 2y ago Moderate: kernel security update
CVE-2024-36978 high 7.8 7.8 FIX rhel rocky sles 2y ago Moderate: kernel security update
CVE-2024-27856 high 8.0 FIX rhel slesdebian debian 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Pro…
CVE-2024-27851 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing maliciously cra…
CVE-2024-27838 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.…
CVE-2024-27820 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS …
CVE-2024-23284 high 8.0 FIX rhel slesdebian debian 2y ago A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, wat…
CVE-2024-23280 high 8.0 FIX rhel slesdebian debian 2y ago An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may …
CVE-2024-23263 high 8.0 FIX rhel slesdebian debian 2y ago A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 1…
CVE-2024-23254 high 8.0 FIX rhel slesdebian debian 2y ago The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfi…
CVE-2023-43010 high 8.0 FIX rhel slesdebian debian 2y ago The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. P…
CVE-2024-9341 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:8846: container-tools:rhel8 security update (Important)
CVE-2024-9680 high 9.5 KEVFIX rhel rockydebian debian 2y ago Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
CVE-2024-43485 high 8.0 FIX rhel rockyalmalinux almalinux 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-43484 high 8.0 FIX rhel rockyalmalinux almalinux 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-43483 high 8.0 FIX rhel rockyalmalinux almalinux 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-38229 high 8.0 FIX rhel rockyalmalinux almalinux 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-8900 high 8.0 FIX rockydebian debian rhel 2y ago An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and T…
CVE-2024-9403 high 8.0 FIX rhel rockydebian debian 2y ago Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code…
CVE-2024-9402 high 8.0 FIX rhel rockydebian debian 2y ago Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-9401 high 8.0 FIX rhel rockydebian debian 2y ago Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2024-9400 high 8.0 FIX rhel rockydebian debian 2y ago A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, …
CVE-2024-9399 high 8.0 FIX rhel rockydebian debian 2y ago A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox E…
CVE-2024-9398 high 8.0 FIX rhel rockydebian debian 2y ago By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vuln…
CVE-2024-9397 high 8.0 FIX rhel rockydebian debian 2y ago A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 1…
CVE-2024-9396 high 8.0 FIX rhel rockydebian debian 2y ago It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131,…
CVE-2024-9394 high 8.0 FIX rhel rockydebian debian 2y ago An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This ac…
CVE-2024-9393 high 8.0 FIX rhel rockydebian debian 2y ago An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This acces…
CVE-2024-9392 high 8.0 FIX rhel rockydebian debian 2y ago A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 12…
CVE-2024-47850 high 8.0 rheldebian debian sles 2y ago RHSA-2024:7463: cups-filters security update (Important)
CVE-2024-47176 high 9.0 EXPFIX rhel rockydebian debian 2y ago RHSA-2024:7463: cups-filters security update (Important)
CVE-2024-47076 high 9.0 EXPFIX rhel rockydebian debian 2y ago RHSA-2024:7463: cups-filters security update (Important)
CVE-2024-45026 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corruption on ESE devices Extent Space Efficient (ESE) or thin provisioned volumes …
CVE-2024-42246 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-42225 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-41097 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: usb: atm: cxacru: fix endpoint checking in cxacru_bind() Syzbot is still reporting quite an old issue [1] that occurs due to inco…
CVE-2024-41071 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-41064 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: avoid possible crash when edev->pdev changes If a PCI device is removed during eeh_pe_report_edev(), edev->pdev will…
CVE-2024-41035 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor Syzbot has identified a bug in usbcore (see the…
CVE-2024-41023 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix task_struct reference leak During the execution of the following stress test with linux-rt: stress-ng --cycl…
CVE-2024-39506 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet In lio_vf_rep_copy_packet() pg_info->page is compared to …
CVE-2024-38601 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-38573 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-38570 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-38562 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-36953 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the vCPU tha…
CVE-2024-36919 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload The session resources are used by FW and driver when ses…
CVE-2024-36899 high 7.0 7.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-36016 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-27022 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-26991 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-26947 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-26931 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update