Skip to main content

CWE archive

CWE-754 CVEs

Programmatic archive

603 CVEs tagged with CWE-75420 Critical, 249 High, 293 Medium, 41 Low, 0 Unrated.

CVE-2024-42159

Published Jul 30, 2024

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Sanitise num_phys Information is stored in mr_sas_port->phy_mask, values larger then size of th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42154

Published Jul 30, 2024

In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4 is at…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42139

Published Jul 30, 2024

In the Linux kernel, the following vulnerability has been resolved: ice: Fix improper extts handling Extts events are disabled and enabled by the application ts2phc. However, in…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-40968

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: MIPS: Octeon: Add PCIe link status check The standard PCIe configuration read-write interface is used to acce…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40963

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: mips: bmips: BCM6358: make sure CBR is correctly set It was discovered that some device have CBR address set…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40933

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: iio: temperature: mlx90635: Fix ERR_PTR dereference in mlx90635_probe() When devm_regmap_init_i2c() fails, re…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39530

Published Jul 11, 2024

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis management daemon (chassisd) of Juniper Networks Junos OS allows an unauthenticated, network-b…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37151

Published Jul 11, 2024

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39559

Published Jul 10, 2024

An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS Evolved may allow a network-based unauthenticated attacker…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39517

Published Jul 10, 2024

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) on Juniper Networks Junos OS and Junos OS Evolved allows an un…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39869

Published Jul 9, 2024

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected products allow to upload certificates. An authenticated attacker could uplo…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21586

Published Jul 1, 2024

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX Series allows an una…

CVSS 7.5 · High

CVE-2024-36481

Published Jun 21, 2024

In the Linux kernel, the following vulnerability has been resolved: tracing/probes: fix error check in parse_btf_field() btf_find_struct_member() might return NULL or an error v…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38355

Published Jun 19, 2024

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.I…

CVSS 7.3 · High

CVE-2024-38461

Published Jun 16, 2024

irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34694

Published Jun 14, 2024

LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered fail…

CVSS 8.1 · High

CVE-2024-5469

Published Jun 14, 2024

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-36128

Published Jun 3, 2024

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numeric length value to the random string generation utility wil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4611

Published May 29, 2024

The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 603 CVEsPage 11 of 25