Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-08 CVE-2024-50203 Out-of-bounds Write vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix address emission with tag-based KASAN enabled When BPF_TRAMP_F_CALL_ORIG is enabled, the address of a bpf_tramp_image struct on the stack is passed during the size calculation pass and an address on the heap is passed during code generation.
local
low complexity
linux CWE-787
7.8
2024-11-08 CVE-2024-50209 Unspecified vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add a check for memory allocation __alloc_pbl() can return error when memory allocation fails. Driver is not checking the status on one of the instances.
local
low complexity
linux
7.8
2024-11-08 CVE-2024-10990 SQL Injection vulnerability in Oretnom23 Online Veterinary Appointment System 1.0
A vulnerability classified as critical was found in SourceCodester Online Veterinary Appointment System 1.0.
network
low complexity
oretnom23 CWE-89
8.8
2024-11-08 CVE-2024-45759 Unspecified vulnerability in Dell Data Domain Operating System
Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability.
local
low complexity
dell
7.3
2024-11-08 CVE-2024-48010 Unspecified vulnerability in Dell Data Domain Operating System
Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability.
network
low complexity
dell
7.2
2024-11-07 CVE-2024-10966 Unspecified vulnerability in Totolink X18 Firmware 9.1.0Cu.2024B20220329
A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329.
network
low complexity
totolink
8.8
2024-11-07 CVE-2024-10967 SQL Injection vulnerability in Anisha E-Health Care System 1.0
A vulnerability was found in code-projects E-Health Care System 1.0.
network
low complexity
anisha CWE-89
7.5
2024-11-07 CVE-2024-10963 A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames.
network
high complexity
CWE-287
7.4
2024-11-07 CVE-2023-1973 A flaw was found in Undertow package.
network
low complexity
7.5
2024-11-07 CVE-2024-50143 Use of Uninitialized Resource vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad Check for overflow when computing alen in udf_current_aext to mitigate later uninit-value use in udf_get_fileshortad KMSAN bug[1]. After applying the patch reproducer did not trigger any issue[2]. [1] https://syzkaller.appspot.com/bug?extid=8901c4560b7ab5c2f9df [2] https://syzkaller.appspot.com/x/log.txt?x=10242227980000
local
low complexity
linux CWE-908
7.8