Wed, Mar 15 · 11:15 PM CDTCVE-2023-28461
9.8/10 · Must read/watchNVDvuln
Summary
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated
CVECVE-2023-28461
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 15 · 11:15 PM CDT
ModifiedWed, Aug 05 · 05:16 AM CDT
Tue, Jul 25 · 07:15 AM CDTCVE-2023-35078
9.8/10 · Must read/watchNVDvuln
Summary
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
CVECVE-2023-35078
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jul 25 · 07:15 AM CDT
ModifiedWed, Aug 05 · 05:16 AM CDT
Wed, Jul 19 · 06:15 PM CDTCVE-2023-3519
9.8/10 · Must read/watchNVDvuln
Summary
Unauthenticated remote code execution
CVECVE-2023-3519
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jul 19 · 06:15 PM CDT
ModifiedWed, Aug 05 · 05:16 AM CDT
Tue, Sep 12 · 07:15 PM CDTCVE-2023-4501
9.8/10 · Must read/watchNVDvuln
Summary
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0 patch updates 8 and 9, and 9.0 patch update 1
CVECVE-2023-4501
SeverityCRITICAL
TypeUPDATED
PublishedTue, Sep 12 · 07:15 PM CDT
ModifiedTue, Aug 04 · 01:17 PM CDT
Wed, Feb 21 · 03:15 PM CSTCVE-2024-26582
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt_done releases them, and we trigger a use-after-free in process_rx_list when we try t
CVECVE-2024-26582
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 21 · 03:15 PM CST
ModifiedTue, Aug 04 · 11:16 AM CDT
Wed, Feb 21 · 03:15 PM CSTCVE-2024-26583
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete() so any code past that point risks touching already freed data. Try to avoid the l
CVECVE-2024-26583
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 21 · 03:15 PM CST
ModifiedTue, Aug 04 · 11:16 AM CDT
Wed, Feb 21 · 03:15 PM CSTCVE-2024-26584
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt} can return -EBUSY instead of -EINPROGRESS in valid situations. For example, when th
CVECVE-2024-26584
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 21 · 03:15 PM CST
ModifiedTue, Aug 04 · 11:16 AM CDT
Wed, Feb 21 · 03:15 PM CSTCVE-2024-26585
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). Reorder scheduling the work before calling complete(). This s
CVECVE-2024-26585
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 21 · 03:15 PM CST
ModifiedTue, Aug 04 · 11:16 AM CDT
Thu, Feb 22 · 05:15 PM CSTCVE-2024-26592
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new TCP connection and its disconnection. It leads to UAF on `struct tcp_transport` in ksmbd_tcp_new_connection() function.
CVECVE-2024-26592
SeverityCRITICAL
TypeUPDATED
PublishedThu, Feb 22 · 05:15 PM CST
ModifiedTue, Aug 04 · 11:16 AM CDT
Wed, Apr 03 · 05:15 PM CDTCVE-2024-26760
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc into a simple kmalloc wrapper"), a bio allocated by bio_kmalloc() must be freed by bio_uninit() and kfree(). That is not done properly for the error c
CVECVE-2024-26760
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 03 · 05:15 PM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Thu, Apr 04 · 09:15 AM CDTCVE-2024-26782
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the new socket has the same value as the original one: as a consequence, on program exit
CVECVE-2024-26782
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 04 · 09:15 AM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Thu, Apr 04 · 09:15 AM CDTCVE-2024-26800
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait until all async decryptions have completed. If one of them fails, tls_do_decryption wi
CVECVE-2024-26800
SeverityCRITICAL
TypeUPDATED
PublishedThu, Apr 04 · 09:15 AM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Mon, Apr 08 · 10:15 AM CDTCVE-2024-26811
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc response to ksmbd kernel server. ksmbd should validate payload size of ipc response from ksmbd.mountd to avoid memory overrun or slab-
CVECVE-2024-26811
SeverityCRITICAL
TypeUPDATED
PublishedMon, Apr 08 · 10:15 AM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Wed, Apr 17 · 11:15 AM CDTCVE-2024-26853
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: igc: avoid returning frame twice in XDP_REDIRECT When a frame can not be transmitted in XDP_REDIRECT (e.g. due to a full queue), it is necessary to free it by calling xdp_return_frame_rx_napi. However, this is the responsibility of the caller of the nd
CVECVE-2024-26853
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 17 · 11:15 AM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Wed, Apr 17 · 11:15 AM CDTCVE-2024-26877
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx - call finalize with bh disabled When calling crypto_finalize_request, BH should be disabled to avoid triggering the following calltrace: ------------[ cut here ]------------ WARNING: CPU: 2 PID: 74 at crypto/crypto_engine.c:58 crypto_fi
CVECVE-2024-26877
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 17 · 11:15 AM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Tue, Aug 29 · 11:15 PM CDTCVE-2023-41265
9.6/10 · Must read/watchNVDvuln
Summary
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the
CVECVE-2023-41265
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 29 · 11:15 PM CDT
ModifiedWed, Aug 05 · 05:16 AM CDT
Wed, Apr 17 · 10:15 AM CDTCVE-2024-26828
9.4/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() In this loop, we step through the buffer and after each item we check if the size_left is greater than the minimum size we need. However, the problem is that "bytes_left" is type ssize_t while sizeof() i
CVECVE-2024-26828
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 17 · 10:15 AM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Fri, Feb 23 · 02:15 PM CSTCVE-2024-26594
9.1/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.
CVECVE-2024-26594
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 23 · 02:15 PM CST
ModifiedTue, Aug 04 · 11:16 AM CDT
Tue, Apr 02 · 07:15 AM CDTCVE-2024-26665
9.1/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the following splat, BUG: KASAN: slab-out-of-bounds in do_csum+0x220/0x240 Read of size 4 at addr ffff88811d402c80 by task netperf
CVECVE-2024-26665
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 02 · 07:15 AM CDT
ModifiedTue, Aug 04 · 11:16 AM CDT
Fri, Feb 23 · 03:15 PM CSTCVE-2024-26598
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF scenario in the case of an LPI translation cache hit racing with an operation that invalidates the cache, such as a DISCARD ITS command. The root of the problem
CVECVE-2024-26598
SeverityHIGH
TypeUPDATED
PublishedFri, Feb 23 · 03:15 PM CST
ModifiedTue, Aug 04 · 11:16 AM CDT
Wed, Apr 03 · 03:15 PM CDTCVE-2024-26689
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This implies before the refcount could be increment here, it was free
CVECVE-2024-26689
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 03 · 03:15 PM CDT
ModifiedTue, Aug 04 · 11:16 AM CDT
Wed, Apr 03 · 05:15 PM CDTCVE-2024-26779
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix race condition on enabling fast-xmit fast-xmit must only be enabled after the sta has been uploaded to the driver, otherwise it could end up passing the not-yet-uploaded sta via drv_tx calls to the driver, leading to potential crash
CVECVE-2024-26779
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 03 · 05:15 PM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Thu, Apr 04 · 09:15 AM CDTCVE-2024-26801
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_error_reset While handling the HCI_EV_HARDWARE_ERROR event, if the underlying BT controller is not responding, the GPIO reset mechanism would free the hci_dev and lead to a use-after-free in hci_error_re
CVECVE-2024-26801
SeverityHIGH
TypeUPDATED
PublishedThu, Apr 04 · 09:15 AM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Wed, Apr 17 · 11:15 AM CDTCVE-2024-26856
8.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: net: sparx5: Fix use after free inside sparx5_del_mact_entry Based on the static analyzis of the code it looks like when an entry from the MAC table was removed, the entry was still used after being freed. More precise the vid of the mac_entry was used
CVECVE-2024-26856
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 17 · 11:15 AM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT
Wed, Apr 17 · 10:15 AM CDTCVE-2024-26822
8.7/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: smb: client: set correct id, uid and cruid for multiuser automounts When uid, gid and cruid are not specified, we need to dynamically set them into the filesystem context used for automounting otherwise they'll end up reusing the values from the parent
CVECVE-2024-26822
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 17 · 10:15 AM CDT
ModifiedTue, Aug 04 · 11:17 AM CDT