Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

698 CVEs tagged with CWE-36727 Critical, 353 High, 271 Medium, 47 Low, 0 Unrated.

CVE-2024-50234

Published Nov 9, 2024

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlegacy: Clear stale interrupts before resuming device iwl4965 fails upon resume from hibernation on m…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50220

Published Nov 9, 2024

In the Linux kernel, the following vulnerability has been resolved: fork: do not invoke uffd on fork if error occurs Patch series "fork: do not expose incomplete mm on fork". D…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50592

Published Nov 8, 2024

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in the Elefant Upda…

CVSS 7.0 · High

CVE-2024-49768

Published Oct 29, 2024

Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (defaults to 8192) long, followed by a secondar…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-49998

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: net: dsa: improve shutdown sequence Alexander Sverdlin presents 2 problems during shutdown with the lan9303 d…

CVSS 4.7 · Medium
evidence mentions
8
Buzz score
32.0
Vendor/product tagsBeta · best-effort

CVE-2024-47494

Published Oct 11, 2024

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to establishe…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47813

Published Oct 9, 2024

Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistratio…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-5803

Published Oct 3, 2024

The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) whe…

CVSS 7.5 · High

CVE-2024-6787

Published Sep 21, 2024

This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an att…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27114

Published Sep 11, 2024

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-fi…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43882

Published Aug 21, 2024

In the Linux kernel, the following vulnerability has been resolved: exec: Fix ToCToU between perm check and set-uid/gid usage When opening a file for exec via do_filp_open(), pe…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7348

Published Aug 8, 2024

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7531

Published Aug 6, 2024

Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affect…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42107

Published Jul 30, 2024

In the Linux kernel, the following vulnerability has been resolved: ice: Don't process extts if PTP is disabled The ice_ptp_extts_event() function can race with ice_ptp_release(…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 326-350 of 698 CVEsPage 14 of 28