Show filters
335,472 Total Results
Displaying 641-650 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-41973

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.
Attacker Value
Unknown

CVE-2024-41972

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.
Attacker Value
Unknown

CVE-2024-41971

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.
Attacker Value
Unknown

CVE-2024-41970

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.
Attacker Value
Unknown

CVE-2023-39180

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective lifetime. An attacker can leverage this to create a denial-of-service condition on affected installations of Linux. Authentication is not required to exploit this vulnerability, but only systems with ksmbd enabled are vulnerable.
0
Attacker Value
Unknown

CVE-2023-39179

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.
0
Attacker Value
Unknown

CVE-2023-39176

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.
0
Attacker Value
Unknown

CVE-2024-48962

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-47208

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-45791

Disclosure Date: November 18, 2024 (last updated November 18, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.
0