A critical vulnerability in NVIDIA Container Toolkit impacts all AI applications in a cloud or on-premise environment that rely on it to access GPU resources. [...]
A vulnerability was found in Linux Kernel up to 5.15.161/6.1.95/6.6.35/6.9.6. It has been declared as critical. This vulnerability affects the function __sock_release in the library /arch/x86/include/asm/atomic64_64.h. The manipulation leads to use after free.
This vulnerability was named CVE-2024-40954. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 5.17.9. Affected is the function input_set_capability of the file drivers/input/input.c of the component Bitmap Handler. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2022-48619. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.7.1 and classified as critical. Affected by this issue is the function radeon_crtc_init of the component Radeon DRM. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2023-52470. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.16.4. It has been classified as critical. Affected is the function usb_kill_urb of the component USB Handler. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2022-48760. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.9.8. It has been declared as critical. Affected by this vulnerability is the function fcntl_setlk of the component filelock. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-41012. The attack needs to be done within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.6.35/6.9.6 and classified as critical. This vulnerability affects the function kzalloc of the component CPUfreq. The manipulation leads to memory leak.
This vulnerability was named CVE-2024-40997. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.17 and classified as critical. This issue affects some unknown processing of the file net/netfilter/nf_tables_api.c of the component Netfilter. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2023-6040. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 5.12.4 and classified as problematic. This vulnerability affects the function __blk_mq_sched_bio_merge of the file /kernel/locking/qspinlock.c of the component kyber. The manipulation leads to improper validation of array index.
This vulnerability was named CVE-2021-46984. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Go-Yaml. It has been rated as critical. This issue affects the function Unmarshal. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2022-28948. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability classified as critical has been found in quic-go 0.37.3. This affects an unknown part of the component Connection ID Handler. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2024-22189. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in CoreDNS up to 1.10.1 and classified as problematic. Affected by this issue is some unknown functionality of the component Resolver. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2023-28452. The attack can only be initiated within the local network. There is no exploit available.
A vulnerability was found in CoreDNS up to 1.10.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to injection.
This vulnerability is uniquely identified as CVE-2023-30464. The attack can only be initiated within the local network. There is no exploit available.
A vulnerability was found in Python Software CPython up to 3.13.0 and classified as problematic. This issue affects some unknown processing of the component http.cookies. The manipulation of the argument cookie leads to resource consumption.
The identification of this vulnerability is CVE-2024-7592. The attack can only be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as critical, has been found in Envolution 1.1.0. Affected by this issue is some unknown functionality of the file modules.php. The manipulation of the argument topic leads to sql injection.
This vulnerability is handled as CVE-2007-4253. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Apple iOS up to 1.1.1. It has been rated as critical. This issue affects some unknown processing of the component Packet Filter. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2010-3830. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Chilkat Software ASP String up to 1.1. Affected by this vulnerability is an unknown functionality in the library ckstring.dll of the component ActiveX Control. The manipulation of the argument first leads to path traversal.
This vulnerability is known as CVE-2007-4252. The attack can be launched remotely. Furthermore, there is an exploit available.
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape. Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape. How the Necro Trojan infiltrated Google Play, again Kryptina RaaS | From Unsellable Cast-Off to Enterprise Ransomware […]