Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

810 CVEs tagged with CWE-90880 Critical, 216 High, 484 Medium, 30 Low, 0 Unrated.

CVE-2024-50143

Published Nov 7, 2024

In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad Check for overflow when computing alen in udf_current_aext t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50110

Published Nov 5, 2024

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix one more kernel-infoleak in algo dumping During fuzz testing, the following issue was discovered:…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8896

Published Oct 29, 2024

A maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior to initialization. A malicious actor can leverage this vulne…

CVSS 7.8 · High

CVE-2024-50035

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: ppp: fix ppp_async_encode() illegal access syzbot reported an issue in ppp_async_encode() [1] In this case,…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50033

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: slip: make slhc_remember() more robust against malicious packets syzbot found that slhc_remember() was missin…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48949

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: igb: Initialize mailbox message for VF reset When a MAC address is not assigned to the VF, that portion of th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50014

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: ext4: fix access to uninitialised lock in fc replay path The following kernel trace can be triggered with fst…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2024-49990

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Check GSC structure validity Sometimes xe_gsc is not initialized when checked at HDCP capability…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-49900

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: jfs: Fix uninit-value access of new_ea in ea_buffer syzbot reports that lzo1x_1_do_compress is using uninit-v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47687

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix invalid mr resource destroy Certain error paths from mlx5_vdpa_dev_add() can end up releasing…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47685

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that nf_reject_ip6_tcphdr_put() was…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-47966

Published Oct 10, 2024

Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulne…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46865

Published Sep 27, 2024

In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NUL…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7022

Published Sep 23, 2024

Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46784

Published Sep 18, 2024

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup Currently napi_disable() gets called duri…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8654

Published Sep 10, 2024

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoD…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8178

Published Sep 5, 2024

The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes vi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45005

Published Sep 4, 2024

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: fix validity interception issue when gisa is switched off We might run into a SIE validity if gisa…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 810 CVEsPage 13 of 33