VulnSea

Tagged “vex”

CVEs tagged vex, newest first.

3567 CVEsRSS

CVE-2024-50014Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: ext4: fix access to uninitialised lock in fc replay path The following kernel trace can be triggered with fstest generic/629 when executed against a filesystem with fa…

In the Linux kernel, the following vulnerability has been resolved: ext4: fix access to uninitialised lock in fc replay path The following kernel trace can be triggered with fstest generic/629 when executed against a filesystem with fa…

▾ Sunlitlinux · linux_kernelEPSS 0.22%via NVD
CVE-2024-49994Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: block: fix integer overflow in BLKSECDISCARD I independently rediscovered commit 22d24a544b0d49bbcbd61c8c0eaf77d3c9297155 block: fix overflow in blk_ioctl_discard()…

In the Linux kernel, the following vulnerability has been resolved: block: fix integer overflow in BLKSECDISCARD I independently rediscovered commit 22d24a544b0d49bbcbd61c8c0eaf77d3c9297155 block: fix overflow in blk_ioctl_discard()…

▾ Sunlitlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-49968Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: ext4: filesystems without casefold feature cannot be mounted with siphash When mounting the ext4 filesystem, if the default hash version is set to DX_HASH_SIPHASH but …

In the Linux kernel, the following vulnerability has been resolved: ext4: filesystems without casefold feature cannot be mounted with siphash When mounting the ext4 filesystem, if the default hash version is set to DX_HASH_SIPHASH but …

▾ Sunlitlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-21536High· 7.5
1y ago

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process …

▾ Twilightchimurai · http-proxy-middlewareEPSS 1.0%via NVD
CVE-2024-9355Medium· 6.5
1y ago

A vulnerability was found in Golang FIPS OpenSSL

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…

▾ Sunlitgolang-fips · github.com/golang-fips/opensslEPSS 0.30%via NVD
CVE-2024-46754High· 7.8⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input…

In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input…

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2024-46741High· 7.8⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In fastrpc_req_mmap()…

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In fastrpc_req_mmap()…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-8775Medium· 5.5
2y ago

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without se…

▾ SunlitRed Hat · ansible-coreEPSS 0.27%via NVD
CVE-2024-7885High· 7.5
2y ago

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTT…

▾ Twilightredhat · build_of_apache_camel_-_hawtioEPSS 2.6%via NVD
CVE-2023-39329Medium· 6.5
2y ago

A flaw was found in OpenJPEG

A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.

▾ Sunlituclouvain · openjpegEPSS 0.59%via NVD
CVE-2023-39327Medium· 4.3
2y ago

A flaw was found in OpenJPEG

A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.

▾ Sunlituclouvain · openjpegEPSS 0.56%via NVD
CVE-2024-3653Medium· 5.3
2y ago

A vulnerability was found in Undertow

A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the…

▾ SunlitRed Hat · undertowEPSS 1.9%via NVD
CVE-2021-47335Medium· 5.5
2y ago

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances As syzbot reported, there is an use-after-free issue during f2fs recovery: Use-after-free …

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances As syzbot reported, there is an use-after-free issue during f2fs recovery: Use-after-free …

▾ Sunlitlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-5042Medium· 6.6
2y ago

A flaw was found in the Submariner project

A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromis…

▾ SunlitRed Hat · submariner-operatorEPSS 0.51%via NVD
CVE-2024-4029Medium· 4.1
2y ago

A vulnerability was found in Wildfly’s management interface

A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to co…

▾ SunlitRed Hat · wildflyEPSS 0.28%via NVD
CVE-2023-6717Medium· 6.0
2y ago

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This is…

▾ SunlitRed Hat · keycloakEPSS 0.71%via NVD
CVE-2024-1249High· 7.4
2y ago

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly i…

▾ TwilightRed Hat · keycloakEPSS 0.44%via NVD
CVE-2024-28869High· 7.5
2y ago

traefik: denial of service (CVE-2024-28869)

An improper handling of exceptional conditions vulnerability was found in Traefik. In affected versions, sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default …

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces (RHOSDS) 3.23EPSS 1.0%via CSAF
CVE-2024-1300Medium· 5.4
2y ago

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL c…

▾ SunlitRed Hat · io.vertx:vertx-coreEPSS 1.1%via NVD
CVE-2024-1023Medium· 6.5PoC
2y ago

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. …

▾ TwilightRed Hat · vertx-coreEPSS 1.7%via NVD
CVE-2024-1313Medium· 6.5
2y ago

grafana: vulnerable to authorization bypass (CVE-2024-1313)

A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2023-5685High· 7.5
2y ago

A flaw was found in XNIO

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).

▾ TwilightRed Hat · xnioEPSS 3.5%via NVD
CVE-2024-1753High· 8.6PoC
2y ago

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the ro…

▾ MidnightRed Hat · buildahEPSS 0.49%via NVD
CVE-2024-26620High· 8.2⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: always filter entire AP matrix The vfio_ap_mdev_filter_matrix function is called whenever a new adapter or domain is assigned to the mdev

In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: always filter entire AP matrix The vfio_ap_mdev_filter_matrix function is called whenever a new adapter or domain is assigned to the mdev. The purpose of…

▾ Twilightlinux · linux_kernelEPSS 0.63%via NVD
CVE-2023-52491High· 7.8⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_run In mtk_jpeg_probe, &jpeg->job_timeout_work is bound with mtk_jpeg_job_tim…

In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_run In mtk_jpeg_probe, &jpeg->job_timeout_work is bound with mtk_jpeg_job_tim…

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2024-1442Medium· 6.0
2y ago

grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)

A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9EPSS 0.80%via CSAF
CVE-2024-27304High· 8.1PoC
2y ago

pgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…

▾ MidnightRed Hat · RHACS 4.3 for RHEL 8EPSS 1.1%via CSAF
CVE-2023-52590High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ocfs2: Avoid touching renamed directory if parent does not change The VFS will not be locking moved directory if its parent does not change

In the Linux kernel, the following vulnerability has been resolved: ocfs2: Avoid touching renamed directory if parent does not change The VFS will not be locking moved directory if its parent does not change. Change ocfs2 rename code t…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2023-52523High· 7.8⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Reject sk_msg egress redirects to non-TCP sockets With a SOCKMAP/SOCKHASH map and an sk_msg program user can steer messages sent from one TCP socket (s1)…

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Reject sk_msg egress redirects to non-TCP sockets With a SOCKMAP/SOCKHASH map and an sk_msg program user can steer messages sent from one TCP socket (s1)…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2023-52509High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ravb: Fix use-after-free issue in ravb_tx_timeout_work() The ravb_stop() should call cancel_work_sync()

In the Linux kernel, the following vulnerability has been resolved: ravb: Fix use-after-free issue in ravb_tx_timeout_work() The ravb_stop() should call cancel_work_sync(). Otherwise, ravb_tx_timeout_work() is possible to use the freed…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVEs tagged “vex” — page 117 · VulnSea