[UPDATE] [high] Linux Kernel (Dirty Frag): Multiple vulnerabilities allow gaining administrator rights
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to gain administrator rights.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to gain administrator rights.
An attacker can exploit multiple vulnerabilities in Xen and Citrix Systems XenServer to escalate privileges, bypass security measures, modify and disclose data, or cause a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in Netty to bypass security measures and manipulate data.
An attacker can exploit multiple vulnerabilities in libssh to gain elevated privileges, bypass security measures, disclose confidential information, trigger a denial-of-service attack, and manipulate data.
A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary code, cause a denial-of-service condition, or disclose confidential information.
A local attacker can exploit multiple vulnerabilities in Red Hat Hardened Images RPMs to conduct a Denial of Service attack.
A local attacker can exploit multiple vulnerabilities in X.Org X11 to gain elevated privileges and execute arbitrary code with root rights.
An attacker can exploit multiple vulnerabilities in Ruby to disclose information, carry out a Denial of Service attack, and execute arbitrary code.
An attacker can exploit multiple vulnerabilities in Netty to bypass security checks, manipulate requests or headers, circumvent certificate checks, and cause a denial of service.
A remote, anonymous attacker can exploit a vulnerability in 7-Zip to execute arbitrary program code.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat OpenShift Container Platform to bypass security measures or trigger a Denial-of-Service condition.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux to execute arbitrary code with user privileges.
A remote, anonymous attacker can exploit multiple vulnerabilities in Apache log4j and Apache Log4cxx to manipulate files.
A remote, authenticated attacker can exploit a vulnerability in IBM WebSphere Application Server to execute arbitrary actions on the server.
An attacker can exploit multiple vulnerabilities in GIMP to execute arbitrary program code and conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Apache Camel to execute arbitrary program code, bypass security measures, perform server-side request forgery, disclose confidential information, or manipulate data.
A local attacker can exploit a vulnerability in GIMP to execute arbitrary program code and to carry out a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux and Red Hat Satellite to disclose information or execute arbitrary code.
An attacker can exploit multiple vulnerabilities in Apache log4j to manipulate files.
A local attacker can exploit a vulnerability in GIMP to conduct a denial of service attack and potentially execute arbitrary code.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct an unspecified attack, potentially triggering a denial-of-service condition, bypassing security measures, or causing memory corruption.
An attacker can exploit multiple vulnerabilities in Red Hat Satellite to gain elevated privileges, including administrative rights, bypass authentication, manipulate data, disclose confidential information, and cause a Denial of Service condition.
An attacker can exploit multiple vulnerabilities in IBM WebSphere Application Server to conduct a Cross-Site Scripting attack and disclose confidential information.
An attacker can exploit multiple vulnerabilities in GStreamer to cause a denial-of-service condition or potentially execute arbitrary code.
A local attacker can exploit a vulnerability in Red Hat Enterprise Linux to execute arbitrary program code with the rights of the service.
A remote, anonymous attacker can exploit multiple vulnerabilities in FasterXML Jackson to bypass protections and authorization rules, manipulate data, disclose information, or cause a Denial-of-Service.
An attacker can exploit multiple vulnerabilities in CUPS to bypass security measures, execute arbitrary code, gain elevated privileges, manipulate data, or cause a denial-of-service condition.
A local attacker can exploit a vulnerability in Red Hat Enterprise Linux (crun) to escalate their privileges.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Ansible Automation Platform to conduct a Denial of Service attack, execute arbitrary code, bypass security measures, manipulate data, disclose confidential information, or conduct cross-site scripting at…
An attacker can exploit multiple vulnerabilities in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira, and Jira Service Management to execute arbitrary code, gain elevated privileges, bypass security measures, manipulate data, disclose confidential information, or …
An attacker can exploit multiple vulnerabilities in DriveLock to disclose information or perform SQL injection, which may lead to privilege escalation.
An attacker can exploit multiple vulnerabilities in Red Hat Ansible Automation Platform to bypass security precautions, disclose information, manipulate data, and cause a denial-of-service condition.
A remote, authenticated attacker can exploit multiple vulnerabilities in Apache CXF to bypass security measures, conduct XML External Entity attacks, manipulate data, or disclose confidential information.
An attacker can exploit multiple vulnerabilities in Golang Go to carry out an unspecified attack.
An attacker can exploit multiple vulnerabilities in GStreamer to conduct a Denial of Service attack, manipulate data, or disclose confidential information.
A remote, authenticated attacker can exploit multiple vulnerabilities in Red Hat Quay to execute arbitrary code and perform server-side request forgery attacks.
An attacker can exploit multiple vulnerabilities in OpenSSL to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, or cause a denial-of-service condition.
A remote, anonymous attacker can exploit multiple vulnerabilities in Netty to bypass security measures, manipulate data, disclose confidential information, or cause a denial-of-service condition.
A remote, anonymous attacker can exploit multiple vulnerabilities in Apache Traffic Server to bypass security measures, disclose or manipulate data, trigger a Denial-of-Service, and potentially achieve code execution.
PIA's POST /v1/upload/sbom endpoint accepts a Bearer JWT and checks its unverified iss claim against an issuer allowlist using Python's urlparse before performing OIDC discovery with requests. Because urlparse and requests/urllib3 parse an authority string containing a backslash …
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to …
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected devi…
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.