Aggregator
CVE-2021-46970 | Linux Kernel up to 5.11.19/5.12.2 pci_generic kernel/workqueue.c check_flush_dependency allocation of resources (abd1510c08a1/ed541cff35cb/0fccbf0a3b69)
8 months ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.11.19/5.12.2. This affects the function check_flush_dependency of the file kernel/workqueue.c of the component pci_generic. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2021-46970. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-46972 | Linux Kernel up to 5.10.34/5.11.18/5.12.1 ovl /file0 ovl_lookup state issue
8 months ago
A vulnerability classified as problematic was found in Linux Kernel up to 5.10.34/5.11.18/5.12.1. This vulnerability affects the function ovl_lookup of the file /file0 of the component ovl. The manipulation leads to state issue.
This vulnerability was named CVE-2021-46972. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-46965 | Linux Kernel up to 5.10.35/5.11.19/5.12.2 physmap-bt1-rom out-of-bounds
8 months ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 5.10.35/5.11.19/5.12.2. This issue affects some unknown processing of the component physmap-bt1-rom. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2021-46965. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-46968 | Linux Kernel up to 5.10.35/5.11.19/5.12.2 zcrypt memory leak
8 months ago
A vulnerability was found in Linux Kernel up to 5.10.35/5.11.19/5.12.2 and classified as critical. Affected by this issue is some unknown functionality of the component zcrypt. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2021-46968. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-46969 | Linux Kernel up to 5.12.2 mhi mhi_queue use after free (a99b661c3187/0ecc1c70dcd3)
8 months ago
A vulnerability was found in Linux Kernel up to 5.12.2. It has been classified as critical. This affects the function mhi_queue of the component mhi. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2021-46969. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-46971 | Linux Kernel up to 5.4.116/5.10.34/5.11.18/5.12.1 perf security_locked_down access control
8 months ago
A vulnerability was found in Linux Kernel up to 5.4.116/5.10.34/5.11.18/5.12.1. It has been declared as critical. This vulnerability affects the function security_locked_down of the component perf. The manipulation leads to improper access controls.
This vulnerability was named CVE-2021-46971. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-46999 | Linux Kernel up to 4.19.190/5.4.119/5.10.37/5.11.21/5.12.4 sctp sctp_sf_do_dupcook_a use after free
8 months ago
A vulnerability was found in Linux Kernel up to 4.19.190/5.4.119/5.10.37/5.11.21/5.12.4. It has been declared as problematic. This vulnerability affects the function sctp_sf_do_dupcook_a of the component sctp. The manipulation leads to use after free.
This vulnerability was named CVE-2021-46999. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47004 | Linux Kernel up to 5.10.37/5.11.21/5.12.4 f2fs get_victim allocation of resources
8 months ago
A vulnerability classified as problematic was found in Linux Kernel up to 5.10.37/5.11.21/5.12.4. Affected by this vulnerability is the function get_victim of the component f2fs. The manipulation leads to allocation of resources.
This vulnerability is known as CVE-2021-47004. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47001 | Linux Kernel up to 5.10.37/5.11.21/5.12.4 xprtrdma rpcrdma_post_recvs denial of service (Nessus ID 213100)
8 months ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 5.10.37/5.11.21/5.12.4. This issue affects the function rpcrdma_post_recvs of the component xprtrdma. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2021-47001. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Green Bay Packers' Online Pro Shop Sacked by Payment Skimmer
8 months ago
Cyberattackers injected the NFL Wild Card team's online Pro Shop with malicious code to steal credit card data from 8,500 fans.
Tara Seals, Managing Editor, News, Dark Reading
Unpatched critical flaws impact Fancy Product Designer WordPress plugin
8 months ago
Premium WordPress plugin Fancy Product Designer from Radykal is vulnerable to two critical severity flaws that remain unfixed in the current latest version. [...]
Bill Toulas
CVE-2023-33672 | Tenda AC8 16.03.34.06 fromSetWifiGusetBasic shareSpeed stack-based overflow
8 months ago
A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. Affected by this issue is the function fromSetWifiGusetBasic. The manipulation of the argument shareSpeed leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2023-33672. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-33673 | Tenda AC8 16.03.34.06 formSetFirewallCfg firewallEn stack-based overflow
8 months ago
A vulnerability was found in Tenda AC8 16.03.34.06. It has been classified as critical. This affects the function formSetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2023-33673. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-33675 | Tenda AC8 16.03.34.06 get_parentControl_list_Info time stack-based overflow
8 months ago
A vulnerability was found in Tenda AC8 16.03.34.06. It has been declared as critical. This vulnerability affects the function get_parentControl_list_Info. The manipulation of the argument time leads to stack-based buffer overflow.
This vulnerability was named CVE-2023-33675. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-33762 | eMedia simpleRedak up to 2.47.23.05 Activity sql injection
8 months ago
A vulnerability was found in eMedia simpleRedak up to 2.47.23.05. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument Activity leads to sql injection.
The identification of this vulnerability is CVE-2023-33762. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-33386 | MarsCTF 1.2.1 Attachment unrestricted upload (Issue 10)
8 months ago
A vulnerability classified as critical was found in MarsCTF 1.2.1. This vulnerability affects unknown code of the component Attachment Handler. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2023-33386. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2020-19028 | Emlog 6.0.0 File Upload /admin/plugin.php information disclosure
8 months ago
A vulnerability was found in Emlog 6.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/plugin.php of the component File Upload Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2020-19028. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-28177 | Mozilla Firefox up to 110 memory corruption
8 months ago
A vulnerability was found in Mozilla Firefox up to 110 and classified as critical. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2023-28177. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-29725 | BT21 x BTS Wallpaper App 12 on Android denial of service
8 months ago
A vulnerability classified as problematic has been found in BT21 x BTS Wallpaper App 12 on Android. Affected is an unknown function. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2023-29725. An attack has to be approached locally. There is no exploit available.
vuldb.com