Search

Found 10,563 results in 879ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-50782 medium 5.5 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug_on in __es_tree_search caused by bad quota inode We got a issue as fllows: ========================================…
CVE-2022-50780 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: net: fix UAF issue in nfqnl_nf_hook_drop() when ops_init() failed When the ops_init() interface is invoked to initialize the net,…
CVE-2022-50777 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented…
CVE-2022-50736 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix immediate work request flush to completion queue Correctly set send queue element opcode during immediate work requ…
CVE-2022-50673 medium 5.5 FIX rocky rhel sles 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in ext4_orphan_cleanup I caught a issue as follows: ====================================================…
CVE-2022-50642 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: zero out stale pointers `cros_typec_get_switch_handles` allocates four pointers when obtaining ty…
CVE-2022-50638 medium 5.5 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug_on in __es_tree_search caused by bad boot loader inode We got a issue as fllows: ==================================…
CVE-2022-50637 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom-hw: Fix memory leak in qcom_cpufreq_hw_read_lut() If "cpu_dev" fails to get opp table in qcom_cpufreq_hw_read_lut()…
CVE-2022-50485 medium 5.5 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: add EXT4_IGET_BAD flag to prevent unexpected bad inode There are many places that will get unhappy (and crash) when ext4_ig…
CVE-2022-50447 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix crash on hci_create_cis_sync When attempting to connect multiple ISO sockets without using DEFER_SETUP m…
CVE-2022-50377 high rhel 2y ago RHSA-2024:2394: kernel security, bug fix, and enhancement update (Important)
CVE-2022-50374 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_{ldisc,serdev}: check percpu_init_rwsem() failure syzbot is reporting NULL pointer dereference at hci_uart_tty_clo…
CVE-2022-50313 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: erofs: fix order >= MAX_ORDER warning due to crafted negative i_size As syzbot reported [1], the root cause is that i_size field …
CVE-2022-50286 medium 5.5 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline When converting files with inline data to extents, dela…
CVE-2022-50277 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: don't allow journal inode to have encrypt flag Mounting a filesystem whose journal inode has the encrypt flag causes a NULL…
CVE-2022-50202 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: PM: hibernate: defer device probing when resuming from hibernation syzbot is reporting hung task at misc_open() [1], for there is…
CVE-2022-50116 medium 5.5 5.5 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix deadlock and link starvation in outgoing data path The current implementation queues up new control and user pack…
CVE-2022-50080 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: tee: add overflow check in register_shm_helper() With special lengths supplied by user space, register_shm_helper() has an intege…
CVE-2022-49977 medium 5.5 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead ftrace_startup does not remove ops from ftrace_o…
CVE-2022-49940 medium 5.5 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() A null pointer dereference can happen when attempting to acces…
CVE-2022-49754 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() Smatch Warning: net/bluetooth/mgmt_util.c:375 mgmt_mesh_add() error: __memcpy…
CVE-2022-49744 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: mm/uffd: fix pte marker when fork() without fork event Patch series "mm: Fixes on pte markers". Patch 1 resolves the syzkiller r…
CVE-2022-49721 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: arm64: ftrace: consistently handle PLTs. Sometimes it is necessary to use a PLT entry to call an ftrace trampoline. This is handl…
CVE-2022-49350 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: net: mdio: unexport __init-annotated mdio_bus_init() EXPORT_SYMBOL and __init is a bad combination because the .init.text section…
CVE-2022-49322 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: tracing: Fix sleeping function called from invalid context on RT kernel When setting bootparams="trace_event=initcall:initcall_st…
CVE-2022-49011 high 8.0 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() As comment of pci_get_domain_bus_and_slot() says, it returns a p…
CVE-2022-48947 medium 5.5 FIX rhel slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix u8 overflow By keep sending L2CAP_CONF_REQ packets, chan->num_conf_rsp increases multiple times and eventua…
CVE-2022-48632 high 8.0 FIX rhel rockydebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() memcpy() is called in a loop while 'operation->length' …
CVE-2022-48554 low 2.5 FIX rheldebian debian rocky 2y ago File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.
CVE-2022-45934 high 8.0 FIX rhel rocky sles 2y ago Important: kernel security, bug fix, and enhancement update
CVE-2022-40090 medium 5.5 FIX rhel slesdebian debian 2y ago Moderate: libtiff security update
CVE-2022-38096 medium 5.5 5.5 FIX rhel rocky sles 2y ago Important: kernel security, bug fix, and enhancement update
CVE-2022-36764 high 8.0 FIX rheldebian debian sles 2y ago RHSA-2024:3017: edk2 security update (Important)
CVE-2022-36763 high 8.0 FIX rheldebian debian sles 2y ago RHSA-2024:3017: edk2 security update (Important)
CVE-2022-33065 medium 5.5 FIX rhel rocky sles 2y ago Moderate: libsndfile security update
CVE-2022-0480 high 8.0 FIX rhel slesdebian debian 2y ago Important: kernel security, bug fix, and enhancement update
CVE-2021-47579 high 8.0 FIX rhel rocky sles 2y ago In the Linux kernel, the following vulnerability has been resolved: ovl: fix warning in ovl_create_real() Syzbot triggered the following warning in ovl_workdir_create() -> ovl_create_real(): if (…
CVE-2021-41072 medium 5.5 FIX rhelarch arch sles 2y ago Moderate: squashfs-tools security update
CVE-2021-41043 medium 5.5 FIX rhel rockydebian debian 2y ago RHSA-2024:0769: tcpdump security update (Moderate)
CVE-2021-40153 medium 5.5 FIX rhelarch arch sles 2y ago Moderate: squashfs-tools security update
CVE-2021-29390 medium 5.5 FIX rheldebian debian rocky 2y ago Moderate: libjpeg-turbo security update
CVE-2020-26555 high 8.0 FIX arch arch rhel rocky 2y ago Important: kernel security, bug fix, and enhancement update
CVE-2020-18770 medium 5.5 FIX rhel rocky sles 2y ago Moderate: zziplib security update
CVE-2014-1745 high 7.1 7.1 FIX sles rhel rocky google 2y ago Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other…
CVE-2024-1753 high 8.0 FIX rhel rockydebian debian 2y ago RHSA-2024:3254: container-tools:rhel8 security update (Important)
CVE-2020-14370 medium 5.5 FIX arch arch sles rocky 2y ago RHSA-2021:0531: container-tools:rhel8 security, bug fix, and enhancement update (Moderate)
CVE-2024-2357 medium 5.5 FIX rhel rockydebian debian 2y ago RHSA-2024:1998: libreswan security update (Moderate)
CVE-2023-45288 high 8.0 FIX rhel rocky sles 2y ago An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HE…
CVE-2024-21012 medium 5.5 FIX rhel rocky sles 2y ago RHSA-2024:1828: java-21-openjdk security update (Moderate)
CVE-2024-3864 low 2.5 FIX rhel rockydebian debian 2y ago Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited…
CVE-2024-3861 low 2.5 FIX rhel rockydebian debian 2y ago If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 11…
CVE-2024-3859 low 2.5 FIX rhel rockydebian debian 2y ago On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox E…
CVE-2024-3857 low 2.5 FIX rhel rockydebian debian 2y ago The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, …
CVE-2024-3854 low 2.5 FIX rhel rockydebian debian 2y ago In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 11…
CVE-2024-3852 low 2.5 FIX rhel rockydebian debian 2y ago GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
CVE-2024-3302 low 2.5 FIX rhel rockydebian debian 2y ago There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firef…
CVE-2024-28835 medium 5.5 FIX rheldebian debian sles 2y ago Moderate: gnutls security update
CVE-2024-28834 medium 5.5 FIX rhel rockydebian debian 2y ago RHSA-2024:1784: gnutls security update (Moderate)
CVE-2024-27316 high 8.0 FIX debian debian rhel rocky 2y ago HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory …
CVE-2024-2609 low 2.5 FIX rhel rockydebian debian 2y ago The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR …
CVE-2024-21085 medium 5.5 FIX rhel rocky sles 2y ago Moderate: java-1.8.0-openjdk security update
CVE-2024-21068 medium 5.5 FIX rhel rocky sles 2y ago Moderate: java-1.8.0-openjdk security update
CVE-2024-21011 medium 5.5 FIX rhel rocky sles 2y ago Moderate: java-1.8.0-openjdk security update
CVE-2023-40551 high 8.0 FIX rhel slesdebian debian 2y ago RHSA-2024:1902: shim security update (Important)
CVE-2023-40550 high 8.0 FIX rhel slesdebian debian 2y ago RHSA-2024:1902: shim security update (Important)
CVE-2023-40549 high 8.0 FIX rhel slesdebian debian 2y ago RHSA-2024:1902: shim security update (Important)
CVE-2023-40548 high 8.0 FIX rhel slesdebian debian 2y ago RHSA-2024:1902: shim security update (Important)
CVE-2023-40547 high 8.0 FIX rhel slesdebian debian 2y ago RHSA-2024:1902: shim security update (Important)
CVE-2023-40546 high 8.0 FIX rhel slesdebian debian 2y ago RHSA-2024:1902: shim security update (Important)
CVE-2024-26859 medium 4.7 4.7 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: net/bnx2x: Prevent access to a freed page in page_pool Fix race condition leading to system crash during EEH error handling Duri…
CVE-2024-26851 medium 5.5 5.5 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: Add protection for bmp length out of range UBSAN load reports an exception of BRK#5515 SHIFT_ISSUE:…
CVE-2023-29483 medium 5.5 FIX rheldebian debian sles 2y ago Moderate: python-dns security update
CVE-2023-6516 high 8.0 FIX rheldebian debian rocky 2y ago Important: bind security update
CVE-2023-5679 high 8.0 FIX rheldebian debian rocky 2y ago Important: bind security update
CVE-2023-5517 high 8.0 FIX rheldebian debian rocky 2y ago Important: bind security update
CVE-2023-4408 high 8.0 FIX rheldebian debian rocky 2y ago Important: bind security update
CVE-2024-1488 high 8.0 FIX rhel rocky sles 2y ago RHSA-2025:0837: unbound security update (Important)
CVE-2024-30156 high 8.0 FIX rhel rockydebian debian 2y ago Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection control flow window, aka a Brok…
CVE-2024-22017 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:1687: nodejs:20 security update (Important)
CVE-2024-21896 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:1687: nodejs:20 security update (Important)
CVE-2024-21891 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:1687: nodejs:20 security update (Important)
CVE-2024-21890 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:1687: nodejs:20 security update (Important)
CVE-2022-48624 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:4256: less security update (Important)
CVE-2024-28219 medium 5.5 FIX rocky slesdebian debian 2y ago RHSA-2024:4227: python-pillow security update (Moderate)
CVE-2024-26659 medium 5.5 5.5 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: xhci: handle isoc Babble and Buffer Overrun events properly xHCI 4.9 explicitly forbids assuming that the xHC has released its ow…
CVE-2023-52425 medium 5.5 FIX rhel rockydebian debian 2y ago RHSA-2024:4259: xmlrpc-c security and bug fix update (Moderate)
CVE-2024-29944 critical 9.5 FIX rhel rockydebian debian 2y ago An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, …
CVE-2024-2616 critical 9.5 FIX rhel rockydebian debian 2y ago RHSA-2024:1484: firefox security update (Critical)
CVE-2024-2614 medium 5.5 FIX rhel rockydebian debian 2y ago Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2024-2612 medium 5.5 FIX rhel rockydebian debian 2y ago If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Fi…
CVE-2024-2611 medium 5.5 FIX rhel rockydebian debian 2y ago A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunder…
CVE-2024-2610 medium 5.5 FIX rhel rockydebian debian 2y ago Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.…
CVE-2024-2608 medium 5.5 FIX rhel rockydebian debian 2y ago `AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an …
CVE-2024-2607 medium 5.5 FIX rhel rockydebian debian 2y ago Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulner…
CVE-2024-21892 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:1687: nodejs:20 security update (Important)
CVE-2024-1936 medium 5.5 FIX rhel slesdebian debian 2y ago RHSA-2024:1494: thunderbird security update (Moderate)
CVE-2024-0743 medium 5.5 FIX rhel rockydebian debian 2y ago An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.
CVE-2023-46809 high 8.0 FIX rhel rocky sles 2y ago RHSA-2024:1687: nodejs:20 security update (Important)
CVE-2024-27281 medium 5.5 FIX rhel rocky sles 2y ago RHSA-2024:4499: ruby security update (Moderate)
CVE-2024-27280 medium 5.5 FIX rhel rocky sles 2y ago RHSA-2024:4499: ruby security update (Moderate)