Show filters
9,044 Total Results
Displaying 261-270 of 9,044
Sort by:
Attacker Value
Unknown

CVE-2024-1151

Disclosure Date: February 11, 2024 (last updated February 26, 2025)
A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and causing a stack overflow. As a result, this can lead to a crash or other related issues.
Attacker Value
Unknown

CVE-2024-25714

Disclosure Date: February 11, 2024 (last updated February 26, 2025)
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)
Attacker Value
Unknown

CVE-2023-6536

Disclosure Date: February 07, 2024 (last updated February 26, 2025)
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.
Attacker Value
Unknown

CVE-2023-6356

Disclosure Date: February 07, 2024 (last updated February 26, 2025)
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and causing kernel panic and a denial of service.
Attacker Value
Unknown

CVE-2023-46838

Disclosure Date: January 29, 2024 (last updated February 26, 2025)
Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred data, these parts are directly translated into what Linux calls SKB fragments. Such converted request parts can, when for a particular SKB they are all of length zero, lead to a de-reference of NULL in core networking code.
Attacker Value
Unknown

CVE-2024-0755

Disclosure Date: January 23, 2024 (last updated February 26, 2025)
Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Attacker Value
Unknown

CVE-2024-0753

Disclosure Date: January 23, 2024 (last updated January 31, 2024)
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Attacker Value
Unknown

CVE-2024-0751

Disclosure Date: January 23, 2024 (last updated February 26, 2025)
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Attacker Value
Unknown

CVE-2024-0750

Disclosure Date: January 23, 2024 (last updated January 31, 2024)
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Attacker Value
Unknown

CVE-2024-0749

Disclosure Date: January 23, 2024 (last updated February 26, 2025)
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.