A vulnerability was found in Apple iOS and iPadOS up to 18.0. It has been rated as critical. This issue affects some unknown processing of the component DCP Firmware Handler. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2024-44299. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.15.167/6.1.112/6.6.53/6.10.12/6.11.1. It has been rated as problematic. This issue affects the function f2fs_lookup of the file fs/f2fs/inode.c. The manipulation leads to state issue.
The identification of this vulnerability is CVE-2024-47690. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 5.15.167/6.1.112/6.6.56/6.11.3 and classified as problematic. This vulnerability affects the function v3d_perfmon_close_file. The manipulation leads to uncontrolled file descriptor consumption.
This vulnerability was named CVE-2024-50031. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.11.1. Affected by this issue is the function nilfs_btree_insert of the component nilfs2. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2024-47699. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in wolfSSL up to 5.6.6 on Linux/Windows and classified as problematic. Affected by this issue is the function RsaPrivateDecryption of the file wolfssl/wolfcrypt/src/rsa.c of the component wolfCrypt. The manipulation leads to improper restriction of software interfaces to hardware features.
This vulnerability is handled as CVE-2024-1545. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in wolfSSL up to 5.6.6 and classified as problematic. This issue affects some unknown processing of the component Packet Handler. The manipulation leads to improper validation of array index.
The identification of this vulnerability is CVE-2024-0901. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic has been found in Linux Kernel up to 5.15.167/6.1.112/6.6.53/6.10.12/6.11.1. This affects the function bond_xdp_get_xmit_slave of the component bonding. The manipulation leads to Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-47734. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. This affects the function vbva_mouse_pointer_shape of the component vboxvideo. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-50134. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in wolfSSL 1.3. It has been declared as critical. This vulnerability affects unknown code of the component Key Handler. The manipulation leads to improper input validation.
This vulnerability was named CVE-2023-3724. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.15.168/6.1.113/6.6.57/6.11.4. This issue affects the function chained_irq_enter of the component pinctrl. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2024-50196. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.11.2. This affects the function journal_reset of the component ocfs2. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2024-49957. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.34/2.35/2.36/2.37/2.38. This issue affects the function pr_function_type of the file prdbg.c. The manipulation leads to memory leak.
The identification of this vulnerability is CVE-2022-47010. The attack can only be done within the local network. There is no exploit available.
A vulnerability was found in Linux Kernel up to 6.11.2. It has been classified as critical. This affects the function memcpy of the file drivers/net/wireless/marvell/mwifiex/scan.c. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-50008. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
An Iranian state hacking group is using custom malware to compromise IoT and OT infrastructure in Israel and the United States. An attack wave from Islamic Revolutionary Guard Corps-affiliated "CyberAv3ngers" swept up fuel management systems made by U.S.-based firm Gilbarco Veeder-Root.
IT Outage, Downtime Procedures Affecting Services at California Healthcare Provider Cybercriminals claim they stole 17 million patient records from a southern California regional healthcare provider that is still struggling with IT and phone systems outages that have been disrupting patient care since the organization was hit by a ransomware attack on Dec. 1.
Also: How Leading Cybersecurity Firms Are Gearing Up for 2025 In the latest weekly update, ISMG editors discussed the shooting death of the UnitedHealthcare CEO and its wider implications for AI-driven decision-making, market strategies for the top cybersecurity companies in 2025, and how these strategies reflect industry trends.
Around 30,000 German IoT Devices Infected From Backdoored Android Applications The German federal information security agency disrupted a botnet that infected thousands of backdoored digital picture frames and media players made with knockoff Android operating systems shipped from China. The agency identified at least 30,000 infected devices.