A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.8.9. This vulnerability affects unknown code of the component xe_migrate. The manipulation results in buffer overflow.
This vulnerability is known as CVE-2024-36948. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.8.9. Impacted is the function make_uffd_wp_pte of the component task_mmu. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-36943. The attack can only be initiated within the local network. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 5.15.158/6.1.90/6.6.30/6.8.9. Impacted is the function fc_remove_host of the component scsi. The manipulation leads to race condition.
This vulnerability is referenced as CVE-2024-36952. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.30/6.8.9. It has been classified as problematic. This impacts the function kfd_suspend_all_processes. Performing manipulation results in privilege escalation.
This vulnerability is cataloged as CVE-2024-36949. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.6.30/6.8.9. It has been declared as problematic. Affected is an unknown function. Executing manipulation can lead to privilege escalation.
This vulnerability is registered as CVE-2024-36951. The attack requires access to the local network. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.8.9. This vulnerability affects the function thermal_debug_tz_remove of the component debugfs. Such manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2024-36956. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.
A vulnerability described as critical has been identified in Linux Kernel up to 6.8.9. Impacted is the function nfsd4_encode_fattr4 of the component NFSD. Executing manipulation can lead to improper initialization.
This vulnerability is handled as CVE-2024-36958. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.1.90/6.6.30/6.8.9 on KS8851. Impacted is the function local_bh_disable/local_bh_enable of the component ks8851. Such manipulation leads to privilege escalation.
This vulnerability is documented as CVE-2024-36962. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.30/6.8.9. Affected by this issue is some unknown functionality of the component iwlwifi. Executing manipulation can lead to memory corruption.
The identification of this vulnerability is CVE-2024-36922. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.
A vulnerability classified as problematic was found in Linux Kernel up to 6.1.90/6.6.30/6.8.9. Affected is the function bsg_reply_buf->reply_buf of the file drivers/scsi/mpi3mr/mpi3mr_app.c. Such manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-36920. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is advised.
Allianz Life has completed the investigation into the cyberattack it suffered in July and determined that nearly 1.5 million individuals are impacted. [...]
Researchers have demonstrated an attack that can break through modern Intel and AMD processor technologies that protect encrypted data stored in memory.
A vulnerability was found in PowerDNS Recursor up to 4.8.0. It has been declared as problematic. This vulnerability affects unknown code of the component DS Record Handler. Such manipulation leads to uncontrolled recursion.
This vulnerability is traded as CVE-2023-22617. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Insyde InsydeH2O up to 5.5. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Save State Register. Performing manipulation results in externally controlled reference.
This vulnerability is reported as CVE-2023-22616. The attacker must have access to the local network to execute the attack. No exploit exists.
A vulnerability described as critical has been identified in Insyde InsydeH2O up to 5.5. Affected is an unknown function of the component IhisiSmm. Executing manipulation can lead to state issue.
The identification of this vulnerability is CVE-2023-22615. The attack needs to be done within the local network. There is no exploit available.
A vulnerability labeled as critical has been found in LangChain up to 0.0.155. This vulnerability affects unknown code of the component URL Handler. Such manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2023-32786. The attack can be launched remotely. No exploit exists.
A vulnerability marked as critical has been reported in Insyde InsydeH2O up to 5.5. This impacts an unknown function of the component ChipsetSvcSmm. Performing manipulation results in memory corruption.
This vulnerability was named CVE-2023-22614. The attack needs to be approached within the local network. There is no available exploit.
We're kicking off the month with a focus on the human element: the first line of defense, but also the path of least resistance for many cybercriminals