Search

Found 5,398 results in 2477ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-44187 high 8.0 FIX rhel rocky sles 2y ago A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, …
CVE-2024-44185 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted we…
CVE-2024-40866 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiting a malicious website may lead to address bar spoofing.
CVE-2024-40789 high 8.0 FIX rhel rocky sles 2y ago An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, vi…
CVE-2024-40782 high 8.0 FIX rhel rocky sles 2y ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionO…
CVE-2024-40780 high 8.0 FIX rhel rocky sles 2y ago An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1…
CVE-2024-40779 high 8.0 FIX rhel rocky sles 2y ago An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1…
CVE-2024-40776 high 8.0 FIX rhel sles rocky 2y ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionO…
CVE-2024-39502 high 7.8 7.8 FIX rhel rocky sles 2y ago Moderate: kernel security update
CVE-2024-36978 high 7.8 7.8 FIX rhel rocky sles 2y ago Moderate: kernel security update
CVE-2024-27856 high 8.0 FIX rhel slesdebian debian 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Pro…
CVE-2024-27851 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing maliciously cra…
CVE-2024-27838 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.…
CVE-2024-27820 high 8.0 FIX rhel rocky sles 2y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS …
CVE-2024-23284 high 8.0 FIX rhel slesdebian debian 2y ago A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, wat…
CVE-2024-23280 high 8.0 FIX rhel slesdebian debian 2y ago An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may …
CVE-2024-23263 high 8.0 FIX rhel slesdebian debian 2y ago A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 1…
CVE-2024-23254 high 8.0 FIX rhel slesdebian debian 2y ago The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfi…
CVE-2023-43010 high 8.0 FIX rhel slesdebian debian 2y ago The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. P…
CVE-2024-9341 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:8846: container-tools:rhel8 security update (Important)
CVE-2024-9680 high 9.5 KEVFIX rhel rockydebian debian 2y ago Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
CVE-2024-43485 high 8.0 FIX rhel rockyalmalinux almalinux 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-43484 high 8.0 FIX rhel rockyalmalinux almalinux 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-43483 high 8.0 FIX rhel rockyalmalinux almalinux 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-38229 high 8.0 FIX rhel rockyalmalinux almalinux 2y ago RHSA-2024:7868: .NET 8.0 security update (Important)
CVE-2024-8900 high 8.0 FIX rockydebian debian rhel 2y ago An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and T…
CVE-2024-9403 high 8.0 FIX rhel rockydebian debian 2y ago Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code…
CVE-2024-9402 high 8.0 FIX rhel rockydebian debian 2y ago Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-9401 high 8.0 FIX rhel rockydebian debian 2y ago Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
CVE-2024-9400 high 8.0 FIX rhel rockydebian debian 2y ago A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, …
CVE-2024-9399 high 8.0 FIX rhel rockydebian debian 2y ago A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox E…
CVE-2024-9398 high 8.0 FIX rhel rockydebian debian 2y ago By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vuln…
CVE-2024-9397 high 8.0 FIX rhel rockydebian debian 2y ago A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 1…
CVE-2024-9396 high 8.0 FIX rhel rockydebian debian 2y ago It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131,…
CVE-2024-9394 high 8.0 FIX rhel rockydebian debian 2y ago An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This ac…
CVE-2024-9393 high 8.0 FIX rhel rockydebian debian 2y ago An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This acces…
CVE-2024-9392 high 8.0 FIX rhel rockydebian debian 2y ago A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 12…
CVE-2024-47850 high 8.0 rheldebian debian sles 2y ago RHSA-2024:7463: cups-filters security update (Important)
CVE-2024-47176 high 9.0 EXPFIX rhel rockydebian debian 2y ago RHSA-2024:7463: cups-filters security update (Important)
CVE-2024-47175 low 3.5 EXPFIX rhel rockydebian debian 2y ago Low: cups security update
CVE-2024-47076 high 9.0 EXPFIX rhel rockydebian debian 2y ago RHSA-2024:7463: cups-filters security update (Important)
CVE-2024-45026 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corruption on ESE devices Extent Space Efficient (ESE) or thin provisioned volumes …
CVE-2024-42246 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-42225 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-41097 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: usb: atm: cxacru: fix endpoint checking in cxacru_bind() Syzbot is still reporting quite an old issue [1] that occurs due to inco…
CVE-2024-41071 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-41064 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: avoid possible crash when edev->pdev changes If a PCI device is removed during eeh_pe_report_edev(), edev->pdev will…
CVE-2024-41035 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor Syzbot has identified a bug in usbcore (see the…
CVE-2024-41023 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix task_struct reference leak During the execution of the following stress test with linux-rt: stress-ng --cycl…
CVE-2024-39506 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet In lio_vf_rep_copy_packet() pg_info->page is compared to …
CVE-2024-38601 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-38573 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-38570 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-38562 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-36953 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the vCPU tha…
CVE-2024-36919 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload The session resources are used by FW and driver when ses…
CVE-2024-36899 high 7.0 7.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-36016 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2024-27022 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-26991 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-26947 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-26931 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-26930 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-26929 high 8.0 FIX rhel slesalmalinux almalinux 2y ago Important: kernel security update
CVE-2024-26769 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try …
CVE-2024-26739 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2024-26665 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the fol…
CVE-2024-26595 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path When calling mlxsw_sp_acl_tcam_region_destroy() from an erro…
CVE-2023-52884 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security update
CVE-2023-52800 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix htt pktlog locking The ath11k active pdevs are protected by RCU but the htt pktlog handling code calling ath11k…
CVE-2023-52798 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix dfs radar event locking The ath11k active pdevs are protected by RCU but the DFS radar event handling code call…
CVE-2023-52439 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security update
CVE-2022-48836 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: Input: aiptek - properly check endpoint type Syzbot reported warning in usb_submit_urb() which is caused by wrong endpoint type. …
CVE-2022-48760 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix hang in usb_kill_urb by adding memory barriers The syzbot fuzzer has identified a bug in which processes hang wait…
CVE-2022-48754 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: phylib: fix potential use-after-free Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call to phy_device_reset…
CVE-2022-48619 high 8.0 FIX rockydebian debian sles 2y ago An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the situation in which a…
CVE-2021-47609 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: Fix string overflow in SCPI genpd driver Without the bound checks for scpi_pd->name, it could result in the b…
CVE-2021-47582 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: USB: core: Make do_proc_control() and do_proc_bulk() killable The USBDEVFS_CONTROL and USBDEVFS_BULK ioctls invoke usb_start_wait…
CVE-2021-47527 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: serial: core: fix transmit-buffer reset and memleak Commit 761ed4a94582 ("tty: serial_core: convert uart_close to use tty_port_cl…
CVE-2021-47466 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: mm, slub: fix potential memoryleak in kmem_cache_open() In error path, the random_seq of slub cache might be leaked. Fix this by…
CVE-2021-47412 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: block: don't call rq_qos_ops->done_bio if the bio isn't tracked rq_qos framework is only applied on request based driver, so: 1)…
CVE-2021-47352 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: virtio-net: Add validation for used length This adds validation for used length (might come from an untrusted device) to avoid da…
CVE-2021-47338 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: fbmem: Do not delete the mode that is still in use The execution of fb_delete_videomode() is not based on the result of the previ…
CVE-2021-47321 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: watchdog: Fix possible use-after-free by calling del_timer_sync() This driver's remove path calls del_timer(). However, that func…
CVE-2021-47289 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: ACPI: fix NULL pointer dereference Commit 71f642833284 ("ACPI: utils: Fix reference counting in for_each_acpi_dev_match()") start…
CVE-2021-47287 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: driver core: auxiliary bus: Fix memory leak when driver_register() fail If driver_register() returns with error we need to free t…
CVE-2021-47097 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: Input: elantech - fix stack out of bound access in elantech_change_report_id() The array param[] in elantech_change_report_id() m…
CVE-2021-46984 high 8.0 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: kyber: fix out of bounds access when preempted __blk_mq_sched_bio_merge() gets the ctx and hctx for the current CPU and passes th…
CVE-2024-34158 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-34155 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:8038: container-tools:rhel8 security update (Important)
CVE-2024-45770 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:6837: pcp security update (Important)
CVE-2024-45769 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:6837: pcp security update (Important)
CVE-2024-6119 high 7.5 7.5 FIX rhel sles rocky opensslnetapp 2y ago Moderate: openssl security update
CVE-2024-45492 critical 9.8 9.8 FIX rhel rockydebian debian libexpat_project 2y ago RHSA-2024:6989: expat security update (Moderate)
CVE-2024-45491 critical 9.8 9.8 FIX rhel rockydebian debian libexpat_project 2y ago RHSA-2024:8859: xmlrpc-c security update (Moderate)
CVE-2024-45490 high 7.5 7.5 FIX rhel rockydebian debian libexpat_project 2y ago RHSA-2024:6989: expat security update (Moderate)
CVE-2024-8394 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:6684: thunderbird security update (Important)
CVE-2024-8387 high 8.0 FIX rhelalmalinux almalinux rocky 2y ago Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-8386 high 8.0 FIX almalinux almalinux rhel rocky 2y ago If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130…
CVE-2024-8385 high 8.0 FIX rhelalmalinux almalinux rocky 2y ago A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2…