Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-11 CVE-2024-45027 Incomplete Cleanup vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup() If xhci_mem_init() fails, it calls into xhci_mem_cleanup() to mop up the damage.
local
low complexity
linux CWE-459
5.5
2024-09-11 CVE-2024-45028 NULL Pointer Dereference vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_test: Fix NULL dereference on allocation failure If the "test->highmem = alloc_pages()" allocation fails then calling __free_pages(test->highmem) will result in a NULL dereference.
local
low complexity
linux CWE-476
5.5
2024-09-11 CVE-2024-45029 Improper Locking vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: Do not mark ACPI devices as irq safe On ACPI machines, the tegra i2c module encounters an issue due to a mutex being called inside a spinlock.
local
low complexity
linux CWE-667
5.5
2024-09-11 CVE-2024-45030 Out-of-bounds Write vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports that the igb driver does not cope well with large MAX_SKB_FRAG values: setting MAX_SKB_FRAG to 45 causes payload corruption on TX. An easy reproducer is to run ssh to connect to the machine.
local
low complexity
linux CWE-787
5.5
2024-09-11 CVE-2024-46672 NULL Pointer Dereference vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion wpa_supplicant 2.11 sends since 1efdba5fdc2c ("Handle PMKSA flush in the driver for SAE/OWE offload cases") SSID based PMKSA del commands. brcmfmac is not prepared and tries to dereference the NULL bssid and pmkid pointers in cfg80211_pmksa.
local
low complexity
linux CWE-476
5.5
2024-09-11 CVE-2024-7312 Open Redirect vulnerability in Payara
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before 5.2022.5, from 5.20.0 before 5.67.0, from 4.1.2.191.0 before 4.1.2.191.50.
network
low complexity
payara CWE-601
6.1
2024-09-11 CVE-2024-43793 Cross-site Scripting vulnerability in Halo
Halo is an open source website building tool.
network
low complexity
halo CWE-79
6.4
2024-09-11 CVE-2024-4465 Incorrect Authorization vulnerability in Nozominetworks CMC and Guardian
An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges learns how to create a specific application request, they might be able to make limited changes to the reporting configuration.
network
high complexity
nozominetworks CWE-863
5.0
2024-09-11 CVE-2024-8646 Open Redirect vulnerability in Eclipse Glassfish
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish. This vulnerability only affects applications that are explicitly deployed to the root context ('/').
network
low complexity
eclipse CWE-601
6.1
2024-09-11 CVE-2024-45786 Authorization Bypass Through User-Controlled Key vulnerability in Reedos Aim-Star 2.0.1
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints.
network
low complexity
reedos CWE-639
6.5