Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Linux Kernel MEDIUM 5.5
CVE-2024-57806

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction atomicity bug when enabling simple quotas Set squota inc…

Fix: 6.12.8+
Fix from $1,600 2025-01-11
Linux Kernel MEDIUM 5.5
CVE-2024-56783

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level cgroup maxim…

Fix: 6.1.120 / 6.6.66+
Fix from $1,600 2025-01-08
Unclassified HIGH 7.5
CVE-2024-8361

In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, …

Mitigation only
Fix from $1,950 2025-01-07
Linux Kernel MEDIUM 5.5
CVE-2024-56705

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Add check for rgby_data memory allocation failure In ia_css_3a_…

Fix: 4.18 / 5.10.231+
Fix from $1,600 2024-12-28
Unclassified MEDIUM 6.5
CVE-2024-7139

Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which resul…

Mitigation only
Fix from $1,600 2024-12-19
Unclassified MEDIUM 6.5
CVE-2024-7138

An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog …

Mitigation only
Fix from $1,600 2024-12-19
Unclassified HIGH 7.5
CVE-2024-53856

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulne…

Mitigation only
Fix from $1,950 2024-12-05
Yocto MEDIUM 6.5
CVE-2024-20139

In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of se…

Fix: after 3.3
Fix from $1,600 2024-12-02
Unclassified HIGH 7.5
CVE-2024-53429

Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.

Mitigation only
Fix from $1,950 2024-11-21
Ios Xr MEDIUM 6.8
CVE-2021-1440

A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Software could allow an unauthent…

Fix: 7.3.1+
Fix from $1,600 2024-11-18
Wsa8845h Firmware MEDIUM 6.5
CVE-2024-23385

Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.

Patch available
Fix from $1,600 2024-11-04
Ud3tn HIGH 7.5
CVE-2024-10455

Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block

No fix yet
Fix from $1,950 2024-10-28
Libsndfile MEDIUM 6.5
CVE-2024-50613

libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.

Fix: after 1.2.2
Fix from $1,600 2024-10-27
Tinyxml2 MEDIUM 6.5
CVE-2024-50614

TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

Fix: after 10.0.0
Fix from $1,600 2024-10-27
Tinyxml2 MEDIUM 6.5
CVE-2024-50615

TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

Fix: after 10.0.0
Fix from $1,600 2024-10-27
Linux Kernel MEDIUM 5.5
CVE-2024-49932

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't readahead the relocation inode on RST On relocation we're doing re…

Fix: 6.11.3+
Fix from $1,600 2024-10-21
Suricata HIGH 7.5
CVE-2024-47522

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid…

Fix: 7.0.7+
Fix from $1,950 2024-10-16
Suricata HIGH 7.5
CVE-2024-45795

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, rules u…

Fix: 7.0.7+
Fix from $1,950 2024-10-16
H2o HIGH 7.5
CVE-2024-45403

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3 requests are cancelled by th…

Fix: 2024-09-04+
Fix from $1,950 2024-10-11
Quicly HIGH 7.5
CVE-2024-45396

Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can expl…

Fix: 2024-10-10+
Fix from $1,950 2024-10-11
Nr15 HIGH 7.5
CVE-2024-20094

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution pr…

Mitigation only
Fix from $1,950 2024-10-07
Enterprise Linux MEDIUM 5.5
CVE-2024-8354

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a U…

Mitigation only
Fix from $1,600 2024-09-19
Linux Kernel MEDIUM 5.5
CVE-2024-46753

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle errors from btrfs_dec_ref() properly In walk_up_proc() we BUG_ON(…

Fix: 5.10.236 / 5.15.180+
Fix from $1,600 2024-09-18
Unclassified HIGH 7.5
CVE-2024-8768

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.

Patch available
Fix from $1,950 2024-09-17
Linux Kernel MEDIUM 5.5
CVE-2024-42251

In the Linux kernel, the following vulnerability has been resolved: mm: page_ref: remove folio_try_get_rcu() The below bug was reported on a non-SM…

Fix: 6.6.42 / 6.9.11+
Fix from $1,600 2024-08-08
Linux Kernel MEDIUM 5.5
CVE-2024-42252

In the Linux kernel, the following vulnerability has been resolved: closures: Change BUG_ON() to WARN_ON() If a BUG_ON() can be hit in the wild, it…

Fix: 6.9.11+
Fix from $1,600 2024-08-08
Wsa8845h Firmware MEDIUM 6.5
CVE-2024-23350

Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the…

Mitigation only
Fix from $1,600 2024-08-05
Nvr4104 4ks2\/l Firmware HIGH 7.5
CVE-2024-39949

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing th…

Fix: 4.003.0000000.1.r.240515+
Fix from $1,950 2024-07-31
Linux Kernel MEDIUM 5.5
CVE-2023-52887

In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: enhanced error handling for tightly received RTS messages in xt…

Fix: 5.4.279 / 5.10.221+
Fix from $1,600 2024-07-29
Linux Kernel MEDIUM 5.5
CVE-2024-41043

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: drop bogus WARN_ON Happens when rules get flushed/d…

Fix: 6.9.10+
Fix from $1,600 2024-07-29