Skip to main content

CWE archive

CWE-617 CVEs

Programmatic archive

808 CVEs tagged with CWE-6175 Critical, 345 High, 426 Medium, 32 Low, 0 Unrated.

CVE-2024-4076

Published Jul 23, 2024

Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 version…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-39509

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: HID: core: remove unnecessary WARN_ON() in implement() Syzkaller hit a warning [1] in a call to implement() w…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39500

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: sock_map: avoid race between sock_map_close and sk_psock_put sk_psock_get will return NULL if the refcount of…

CVSS 7.8 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2024-39497

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, MAP_PRIVATE) Lack of check for copy-on-write (COW) mapping…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39697

Published Jul 9, 2024

phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-boun…

CVSS 8.6 · High

CVE-2024-38306

Published Jun 25, 2024

In the Linux kernel, the following vulnerability has been resolved: btrfs: protect folio::private when attaching extent buffer folios [BUG] Since v6.8 there are rare kernel cras…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-52831

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: cpu/hotplug: Don't offline the last non-isolated CPU If a system has isolated CPUs via the "isolcpus=" comman…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47351

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix races between xattr_{set|get} and listxattr operations UBIFS may occur some problems with concurre…

CVSS 7.8 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2021-47315

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: memory: fsl_ifc: fix leak of IO mapping on probe failure On probe error the driver should unmap the IO memory…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47305

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: dma-buf/sync_file: Don't leak fences on merge failure Each add_fence() call does a dma_fence_get() on the rel…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36000

Published May 20, 2024

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix missing hugetlb_lock for resv uncharge There is a recent report on UFFDIO_COPY over hugetlb:…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35957

Published May 20, 2024

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix WARN_ON in iommu probe path Commit 1a75cc710b95 ("iommu/vt-d: Use rbtree to track iommu probe…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35884

Published May 19, 2024

In the Linux kernel, the following vulnerability has been resolved: udp: do not accept non-tunnel GSO skbs landing in a tunnel When rx-udp-gro-forwarding is enabled UDP packets…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
33.5
Vendor/product tagsBeta · best-effort

CVE-2024-3374

Published May 14, 2024

An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33263

Published May 14, 2024

QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34475

Published May 5, 2024

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-26946

Published May 1, 2024

In the Linux kernel, the following vulnerability has been resolved: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address Read from an unsafe address with copy…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26937

Published May 1, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Reset queue_priority_hint on parking Originally, with strict in order execution, we could comple…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48633

Published Apr 28, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix WARN_ON(lock->magic != lock) error psb_gem_unpin() calls dma_resv_lock() but the underlying w…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-33255

Published Apr 26, 2024

Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31744

Published Apr 19, 2024

In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service att…

CVSS 7.5 · High

CVE-2024-32475

Published Apr 18, 2024

Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3567

Published Apr 10, 2024

A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fra…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 808 CVEsPage 14 of 33