Aggregator
CVE-2024-33014 | Qualcomm Snapdragon Auto up to QCM5430 Response Frame buffer over-read
5 days ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables and Snapdragon Wired Infrastructure and Networking. It has been classified as critical. Affected is an unknown function of the component Response Frame Handler. The manipulation leads to buffer over-read.
This vulnerability is traded as CVE-2024-33014. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46778 | Linux Kernel up to 6.10.9 AMD Display CalculateSwathAndDETConfiguration_params_st null pointer dereference (4e2b49a85e79/a7b38c785209)
5 days ago
A vulnerability was found in Linux Kernel up to 6.10.9. It has been classified as problematic. This affects the function CalculateSwathAndDETConfiguration_params_st of the component AMD Display. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2024-46778. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46789 | Linux Kernel up to 6.10.9 prepare_slab_obj_exts_hook allocation of resources (2d476c86ba47/ab7ca09520e9)
5 days ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.10.9. This affects the function prepare_slab_obj_exts_hook. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-46789. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46776 | Linux Kernel up to 6.6.50/6.10.9 AMD Display null pointer dereference (874e3bb302f9/adc74d25cdbb/3a82f62b0d9d)
5 days ago
A vulnerability was found in Linux Kernel up to 6.6.50/6.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the component AMD Display. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-46776. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46777 | Linux Kernel up to 6.10.9 udf memory corruption (Nessus ID 208053)
5 days ago
A vulnerability was found in Linux Kernel up to 6.10.9. It has been classified as critical. This affects an unknown part of the component udf. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-46777. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46774 | Linux Kernel up to 6.10.9 Speculative Execution sys_rtas stack-based overflow (68d815648094/0974d03eb479)
5 days ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.10.9. Affected is the function sys_rtas of the component Speculative Execution. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2024-46774. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46775 | Linux Kernel up to 6.10.9 AMD Display return value (5639a3048c70/673f816b9e1e / Nessus ID 208720)
5 days ago
A vulnerability has been found in Linux Kernel up to 6.10.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component AMD Display. The manipulation leads to unchecked return value.
This vulnerability is known as CVE-2024-46775. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46780 | Linux Kernel up to 6.10.9 nilfs2 null pointer dereference (Nessus ID 208099)
5 days ago
A vulnerability was found in Linux Kernel up to 6.10.9. It has been rated as critical. This issue affects some unknown processing of the component nilfs2. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2024-46780. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46794 | Linux Kernel up to 6.1.109/6.6.50/6.10.9 tdx mmio_read initialization (Nessus ID 208099)
5 days ago
A vulnerability was found in Linux Kernel up to 6.1.109/6.6.50/6.10.9. It has been classified as problematic. Affected is the function mmio_read of the component tdx. The manipulation leads to improper initialization.
This vulnerability is traded as CVE-2024-46794. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46812 | Linux Kernel up to 6.1.108/6.6.49/6.10.8 AMD Display Privilege Escalation (Nessus ID 208099)
5 days ago
A vulnerability has been found in Linux Kernel up to 6.1.108/6.6.49/6.10.8 and classified as problematic. This vulnerability affects unknown code of the component AMD Display. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2024-46812. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46815 | Linux Kernel up to 6.10.8 AMD Display num_valid_sets information disclosure (Nessus ID 208099)
5 days ago
A vulnerability was found in Linux Kernel up to 6.10.8. It has been classified as problematic. Affected is the function num_valid_sets of the component AMD Display. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-46815. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46768 | Linux Kernel up to 6.6.50/6.10.9 hwmon null pointer dereference (217539e994e5/4b19c83ba108/a54da9df75cd)
5 days ago
A vulnerability was found in Linux Kernel up to 6.6.50/6.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the component hwmon. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-46768. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46771 | Linux Kernel up to 6.10.9 bcm_connect allocation of resources (Nessus ID 208099)
5 days ago
A vulnerability classified as problematic has been found in Linux Kernel up to 6.10.9. This affects the function bcm_connect. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-46771. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-35847 | Agentejo Cockpit up to 0.11.1 Controller/Auth.php resetpassword sql injection (EDB-50185)
5 days ago
A vulnerability was found in Agentejo Cockpit up to 0.11.1 and classified as critical. Affected by this issue is the function resetpassword of the file Controller/Auth.php. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2020-35847. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Fintech giant Finastra investigates data breach after SFTP hack
5 days ago
Finastra has confirmed it warned customers of a cybersecurity incident after a threat actor began selling allegedly stolen data on a hacking forum. [...]
Bill Toulas
CVE-1999-0009 | ISC BIND 4.9.6/8.1/8.1.1 iquery memory corruption (EDB-19111 / Nessus ID 16871)
5 days ago
A vulnerability, which was classified as very critical, was found in ISC BIND 4.9.6/8.1/8.1.1. Affected is an unknown function of the component iquery. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-1999-0009. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
MITRE shares 2024's top 25 most dangerous software weaknesses
5 days ago
MITRE has shared this year's top 25 list of the most common and dangerous software weaknesses behind more than 31,000 vulnerabilities disclosed between June 2023 and June 2024. [...]
Sergiu Gatlan
China's 'Liminal Panda' APT Attacks Telcos, Steals Phone Data
5 days ago
In US Senate testimony, a CrowdStrike exec explained how this advanced persistent threat penetrated telcos in Asia and Africa, gathering SMS messages, unique identifiers, and other metadata along the way.
Nate Nelson, Contributing Writer
CVE-2023-52265 | IDURAR up to 2.0.1 PATCH Request /api/email/update cross site scripting
5 days 1 hour ago
A vulnerability classified as problematic was found in IDURAR up to 2.0.1. Affected by this vulnerability is an unknown functionality of the file /api/email/update of the component PATCH Request Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2023-52265. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com