U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cleo Harmony, VLTrader, and LexiCom flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability CVE-2024-50623 (CVSS score 8.8), which impacts multiple Cleo products to its Known Exploited Vulnerabilities (KEV) catalog. “Cleo has identified an unrestricted file upload and download vulnerability (CVE-2024-50623) […]
A vulnerability classified as problematic was found in Linux Kernel up to 6.1.118/6.6.62/6.11.9. Affected by this vulnerability is the function get_page of the component Page Refcount Handler. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-53138. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Linux Kernel up to 6.6.61/6.11.8. Affected is the function tcp_write_timer_handler of the component SMB Client. The manipulation leads to improper update of reference count.
This vulnerability is traded as CVE-2024-53095. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.1.118/6.6.62/6.11.9. It has been rated as problematic. This issue affects the function fs_core in the library lib/refcount.c. The manipulation leads to race condition.
The identification of this vulnerability is CVE-2024-53121. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.1.118/6.6.62/6.11.9. It has been classified as problematic. Affected is the function vdpa_mgmtdev_get_classes. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2024-53110. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.6.60/6.11.7 and classified as critical. This vulnerability affects the function net_device_ops::ndo_set_vf_mac. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-50298. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.