[UPDATE] [high] Linux Kernel: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in the Linux Kernel to create a denial-of-service condition or carry out other unspecified attacks.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to create a denial-of-service condition or carry out other unspecified attacks.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack or achieve unspecified effects.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to carry out a denial of service attack or achieve unspecified effects.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack and cause other unspecified effects.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack and unspecified attacks.
An attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a denial of service attack or achieve other unspecified impacts.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to create a Denial of Service state and cause unspecified effects.
A remote attacker can exploit multiple vulnerabilities in the Linux Kernel to compromise confidentiality, integrity, and availability.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to carry out unspecified attacks that may lead to a denial-of-service condition or cause memory corruption.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to carry out unspecified attacks that may lead to a denial-of-service condition or cause memory corruption.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to perform a denial of service attack or achieve other unspecified effects.
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the mailerpress/v1/contact endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated…
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registe…
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated at…
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and …
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this lab…
An attacker can exploit multiple vulnerabilities in the Linux Kernel to carry out an unspecified attack, potentially bypassing security measures, causing a denial-of-service state, or disclosing confidential information.
A remote attacker can exploit multiple vulnerabilities in the Linux Kernel to bypass security measures, cause a denial-of-service condition, and achieve further unspecified impacts.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to bypass security measures, cause a denial of service, and potentially execute code.
An attacker can exploit multiple vulnerabilities in IBM WebSphere Application Server Liberty and IBM WebSphere Application Server to execute arbitrary code, escalate privileges, conduct a Denial of Service attack, disclose information, manipulate files, perform a Cross-Site Scrip…
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct unspecified attacks, which may include DoS attacks, information disclosure, memory corruption, or bypassing security measures.
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated…
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in WP Royal Royal Elementor Addons ausnutzen, um Informationen offenzulegen.
Ein Angreifer kann mehrere Schwachstellen in PHP ausnutzen, um SQL-Injection durchzuführen, beliebigen Code auszuführen, Daten zu manipulieren oder einen Denial-of-Service-Zustand auszulösen.
A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the p…
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service ma…
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values a…
An attacker can exploit multiple vulnerabilities in IBM App Connect Enterprise to disclose information, execute arbitrary code, and manipulate files.
A remote, anonymous attacker can exploit a vulnerability in Ruby on Rails to disclose information, which may lead to remote code execution or lateral movement.
A local attacker can exploit a vulnerability in ImageMagick to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Xen to escalate privileges, disclose confidential information, or trigger a Denial-of-Service condition.
An attacker can exploit multiple vulnerabilities in VMware ESXi, VMware vCenter Server, VMware Workstation, and VMware Fusion to cause a Denial of Service, disclose information, bypass security measures, and execute code.
An attacker can exploit multiple vulnerabilities in Samba to disclose confidential information, bypass security measures, cause a denial-of-service condition, or manipulate data.
A remote, anonymous attacker can exploit multiple vulnerabilities in Erlang/OTP to perform a denial of service attack, execute arbitrary code, bypass security measures, and manipulate or disclose data.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in ImageMagick to disclose information.
An attacker can exploit multiple vulnerabilities in IBM App Connect Enterprise to conduct a denial of service attack, disclose information, manipulate files, perform a cross-site scripting attack, and bypass security measures.
An attacker can exploit multiple vulnerabilities in IBM WebSphere Application Server Liberty to conduct a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Internet Systems Consortium BIND to bypass security measures, manipulate data, disclose confidential information, or trigger a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in Mozilla Firefox and Mozilla Firefox ESR to execute arbitrary code, bypass security measures, disclose confidential information, escalate permissions, perform sandbox escapes, manipulate data, trigger a denial-of-service conditio…
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Ansible Automation Platform to bypass security measures, conduct cross-site scripting attacks, manipulate data, trigger a denial-of-service condition, or execute arbitrary code.
A remote, anonymous, or authenticated attacker can exploit multiple vulnerabilities in Oracle Java SE to compromise confidentiality, integrity, and availability.
A remote, anonymous attacker can exploit a vulnerability in helm to carry out a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to gain administrator rights, bypass security measures, manipulate data, and trigger a Denial-of-Service condition.
A remote, anonymous attacker can exploit a vulnerability in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty to bypass security measures.
An attacker can exploit multiple vulnerabilities in IBM Langflow Desktop to execute arbitrary program code, bypass security precautions, and disclose information.
A local attacker can exploit a vulnerability in ImageMagick to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Apache Tomcat to bypass security measures and disclose information.
An attacker can exploit multiple vulnerabilities in Mozilla Firefox to conduct an unspecified attack.