Microsoft has confirmed that, since November 12, some Windows 10 users have been unable to update or uninstall packaged applications like Microsoft Teams. [...]
A vulnerability classified as problematic has been found in Keycloak. This affects the function SearchQueryUtils. The manipulation leads to inefficient regular expression complexity.
This vulnerability is uniquely identified as CVE-2024-10270. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability was found in Keycloak. It has been rated as critical. Affected by this issue is some unknown functionality of the component mTLS Handler. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2024-10039. The attack needs to be done within the local network. There is no exploit available.
A vulnerability was found in Keycloak up to 26. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Proxy Header Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-9666. The attack can only be initiated within the local network. There is no exploit available.
A vulnerability was found in authentik. It has been classified as problematic. Affected is an unknown function of the file /-/metrics/. The manipulation of the argument SECRET_KEY leads to observable timing discrepancy.
This vulnerability is traded as CVE-2024-52307. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.1.117/6.6.61/6.11.8 and classified as critical. This issue affects the function scan_work of the component nvme-multipath. The manipulation leads to deadlock.
The identification of this vulnerability is CVE-2024-53093. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.11.8 and classified as problematic. This vulnerability affects the function afs_wake_up_async_call. The manipulation leads to uncontrolled recursion.
This vulnerability was named CVE-2024-53090. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.61/6.11.8. This affects the function sendpage_ok of the component RDMA. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-53094. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Gibbon up to 27.0.00. Affected by this issue is some unknown functionality of the file /Gibbon/modules/User Admin/user_manage_editProcess.php.. The manipulation of the argument email leads to cross site scripting.
This vulnerability is handled as CVE-2024-51337. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.6.61/6.11.8. Affected by this vulnerability is the function tls_sw_ctx_rx of the component bpf. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2024-53091. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Linux Kernel up to 6.6.61/6.11.8. Affected is the function tcp_write_timer_handler of the component SMB Client. The manipulation leads to improper update of reference count.
This vulnerability is traded as CVE-2024-53095. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.11.8. It has been rated as critical. This issue affects some unknown processing of the component LoongArch. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-53089. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.11.8. It has been declared as problematic. This vulnerability affects the function vp_modern_avq_cleanup. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-53092. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
Four of the arrested individuals of the cybercriminal gang, known for hacking MGM and Caesars, are American, all of whom could face up to 27 years in prison for the charges against them.
A vulnerability was found in Totolink A810R 4.1.2cu.5182_B20201102. It has been classified as critical. This affects an unknown part of the file infostat.cgi. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-53334. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Totolink A810R 4.1.2cu.5182_B20201102 and classified as critical. Affected by this issue is some unknown functionality of the file downloadFlile.cgi. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2024-53335. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in TP-Link TL-IPC42C 4.0_20211227_1.0.16 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to command injection.
This vulnerability is known as CVE-2024-48288. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in Linksys E3000 1.0.06.002_US. Affected is the function diag_ping_start. The manipulation leads to command injection.
This vulnerability is traded as CVE-2024-48286. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, has been found in Zimbra Collaboration Suite 9.0/10.0. This issue affects some unknown processing of the component Webmail Modern UI. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-45194. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.