A vulnerability has been found in dcgui 0.2/0.2.1 and classified as critical. This vulnerability affects unknown code of the component Directory Parser. The manipulation leads to path traversal.
This vulnerability was named CVE-2003-0076. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.11.2 and classified as critical. Affected by this issue is the function ACPI_ALLOCATE_ZEROED. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-49962. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.11.2. This affects the function journal_reset of the component ocfs2. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2024-49957. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.6.54/6.10.13/6.11.2 and classified as critical. This vulnerability affects the function ext4_handle_error. The manipulation leads to use after free.
This vulnerability was named CVE-2024-49960. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.11.2. It has been declared as critical. This vulnerability affects the function clk_prepare_enable of the component stm32f7. The manipulation leads to deadlock.
This vulnerability was named CVE-2024-49985. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.54/6.10.13/6.11.2. It has been classified as critical. Affected is the function nf_link_info of the file net.c of the component bpftool. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-49987. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.54/6.10.13/6.11.2. It has been declared as critical. Affected by this vulnerability is the function ksmbd_conn. The manipulation leads to improper update of reference count.
This vulnerability is known as CVE-2024-49988. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.10.13/6.11.2 and classified as critical. Affected by this vulnerability is the function xe_gsc of the component HDCP. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-49990. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.54/6.10.13/6.11.2. It has been classified as critical. This affects the function amdkfd_free_gtt_mem. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-49991. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability was named CVE-2024-10335. The attack can be initiated remotely. Furthermore, there is an exploit available.
The initial researcher advisory only mentions the parameter "username" to be affected. But it must be assumed that the parameter "password" is affected as well.
A vulnerability was found in SourceCodeHero Clothes Recommendation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/index.php of the component Admin Login Page. The manipulation of the argument t1 leads to sql injection.
The identification of this vulnerability is CVE-2024-10336. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical has been found in Zimbra Collaboration Suite 8.8.15/9.0. Affected is an unknown function of the component LMAP/SMTP. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2023-26562. The attack can only be initiated within the local network. There is no exploit available.
A vulnerability was found in Tenda AC8 16.03.34.06. It has been declared as critical. Affected by this vulnerability is the function compare_parentcontrol_time of the file /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-10123. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
This is not the same issue like CVE-2023-33671.
A vulnerability classified as critical was found in Tenda AC8 16.03.34.06. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to stack-based buffer overflow.
This vulnerability was named CVE-2024-10130. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.