NA - CVE-2024-25631 - Cilium is a networking, observability, and...
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic...
NA - CVE-2023-52435 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: net: prevent mss overflow in skb_segment() Once again syzbot is able to crash the kernel in skb_segment() [1] GSO_BY_FRAGS is...
NA - CVE-2024-26135 - MeshCentral is a full computer management web...
MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is the primary...
NA - CVE-2023-46967 - Cross Site Scripting vulnerability in the...
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.
NA - CVE-2023-49034 - Cross Site Scripting (XSS) vulnerability in...
Cross Site Scripting (XSS) vulnerability in ProjeQtOr 11.0.2 allows a remote attacker to execute arbitrary code via a crafted script to thecheckvalidHtmlText function in the ack.php and...
NA - CVE-2023-52436 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. This...
NA - CVE-2023-52437 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d" This reverts commit 5e2cf333b7bd5d3e62595a44d598a254c697cd74. That...
NA - CVE-2023-52438 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used during the shrinker's callback, which...
NA - CVE-2023-52439 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 -------------------------------------------------------...
NA - CVE-2024-25141 - When ssl was enabled for Mongo Hook, default...
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to...