Show filters
335,472 Total Results
Displaying 641-650 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2024-41973
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.
0
Attacker Value
Unknown
CVE-2024-41972
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.
0
Attacker Value
Unknown
CVE-2024-41971
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.
0
Attacker Value
Unknown
CVE-2024-41970
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.
0
Attacker Value
Unknown
CVE-2023-39180
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.
0
Attacker Value
Unknown
CVE-2023-39179
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.
0
Attacker Value
Unknown
CVE-2023-39176
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.
0
Attacker Value
Unknown
CVE-2024-48962
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.17.
Users are recommended to upgrade to version 18.12.17, which fixes the issue.
0
Attacker Value
Unknown
CVE-2024-47208
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.17.
Users are recommended to upgrade to version 18.12.17, which fixes the issue.
0
Attacker Value
Unknown
CVE-2024-45791
Disclosure Date: November 18, 2024 (last updated November 18, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat: before 1.6.1.
Users are recommended to upgrade to version 1.6.1, which fixes the issue.
0