A vulnerability classified as critical has been found in Linux Kernel up to 6.8.1. This affects the function stv0367_writereg of the file drivers/media/dvb-frontends/stv0367.c of the component dvb-frontends. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-27075. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.8.1 and classified as critical. Affected by this vulnerability is the function go7007_load_encoder of the component Media. The manipulation leads to memory leak.
This vulnerability is known as CVE-2024-27074. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.8.1 and classified as critical. Affected by this issue is the function v4l2_ctrl_handler of the component imx. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2024-27076. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.8.1. It has been declared as critical. Affected by this vulnerability is the function usbtv_video_free of the component Media. The manipulation leads to deadlock.
This vulnerability is known as CVE-2024-27072. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A few months ago I was looking at the filesystem MCP server from Anthropic.
The server allows to give an AI, like Claude Desktop, access to the local filesystem to read files or edit them and so forth.
I was curious about access control and in the documentation there is a configuration setting to set allowedDirectories, which the AI should be allowed access to:
As you can see the example shows two folders being allowlisted for access.
A vulnerability has been found in Linux Kernel up to 6.8.1 and classified as problematic. This vulnerability affects the function ovl_verify_area. The manipulation leads to reachable assertion.
This vulnerability was named CVE-2024-27069. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.8.1. It has been classified as critical. Affected is the function f2fs_filemap_fault in the library lib/dump_stack.c. The manipulation leads to use after free.
This vulnerability is traded as CVE-2024-27070. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.8.1. Affected is the function hx8357_probe of the component backlight. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-27071. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.22/6.7/6.7.10/6.8.1 and classified as critical. Affected by this issue is the function WARN of the component evtchn. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-27067. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.22/6.7.10/6.8.1. This affects the function devm_krealloc of the component lvts_thermal. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2024-27068. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Giombetti phpPowerCards 2.0. Affected is an unknown function of the file pagenumber.inc.php. The manipulation of the argument subcat leads to cross site scripting.
This vulnerability is traded as CVE-2009-4469. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability has been found in phpMyBackupPro 2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file get_file.php. The manipulation of the argument view leads to path traversal.
This vulnerability is known as CVE-2009-4050. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in phpMyFAQ 0.65. It has been classified as problematic. Affected is an unknown function of the file index.php. The manipulation of the argument question leads to cross site scripting.
This vulnerability is traded as CVE-2009-4780. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Ikemcg phpInstantGallery 1.1. Affected is an unknown function of the file admin.php. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2009-4446. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.22/6.7.10/6.8.1. Affected by this issue is the function use_dma_api of the component virtio. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2024-27066. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.23/6.7.11/6.8.2. It has been rated as critical. Affected by this issue is the function get_device_state of the component netdev. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-27063. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.22/6.7.10/6.8.1. Affected is the function nft_netdev_register_hooks of the component Netfilter. The manipulation leads to memory leak.
This vulnerability is traded as CVE-2024-27064. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.