⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2024-11614 created 8 months, 1 week ago
Dpdk: denial of service from malicious guest on hypervisors using dpdk vhost library

An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.

dpdk
*
<21.11-4
openvswitch
openvswitch3.0
openvswitch3.1
*
openvswitch3.2
openvswitch3.3
*
openvswitch3.4
*
openvswitch2.10
openvswitch2.11
openvswitch2.12
openvswitch2.13
openvswitch2.15
openvswitch2.16
openvswitch2.17

pkgs.dpdk

Set of libraries and drivers for fast packet processing

pkgs.openvswitch

Multilayer virtual switch

pkgs.openvswitch-dpdk

Multilayer virtual switch

pkgs.linuxPackages_zen.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_6_1.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages_zen.dpdk.x86_64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_5_10.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages_zen.dpdk.aarch64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_libre.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_zen.odp-dpdk.x86_64-linux

Open Data Plane optimized for DPDK

pkgs.linuxPackages_zen.odp-dpdk.aarch64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_libre.odp-dpdk

Open Data Plane optimized for DPDK

pkgs.linuxPackages_lqx.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_zen.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_libre.dpdk-kmods

Kernel modules for DPDK

pkgs.linuxPackages-libre.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages-libre.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_latest.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_xanmod.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_latest.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_4_hardened.odp-dpdk

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_5_10.dpdk.x86_64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_5_10.dpdk.aarch64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages_6_1_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_latest-libre.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_5_10_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_5_15_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_6_11_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_6_1_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_latest-libre.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_xanmod_stable.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_5_10_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_5_15_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_6_11_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10.odp-dpdk.x86_64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_5_10.odp-dpdk.aarch64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_5_4.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_1.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_6.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_15.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_4.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_1.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_11.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_12.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_6.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_15.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_11.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_12.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.dpdk.x86_64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_latest_libre.dpdk.aarch64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.odp-dpdk.x86_64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.odp-dpdk.aarch64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_6_1_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_15_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_11_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_1_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_15_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_11_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK
Package maintainers: 9
CVE-2023-52355
7.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 8 months, 1 week ago
Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

iv
tkimg
libtiff
<4.6.0
mingw-libtiff
compat-libtiff3

pkgs.libtiff

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-darwin

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-darwin

Library and utilities for working with the TIFF image file format
Package maintainers: 7
CVE-2023-6228
3.3 LOW
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 8 months, 1 week ago
Libtiff: heap-based buffer overflow in cpstriptotile() in tools/tiffcp.c

An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.

tkimg
libtiff
*
mingw-libtiff
compat-libtiff3

pkgs.libtiff

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-darwin

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-darwin

Library and utilities for working with the TIFF image file format
Package maintainers: 7
CVE-2024-54350
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 8 months, 1 week ago
WordPress hmd theme <= 2.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

hmd
=<2.0

pkgs.openhmd

Library API and drivers immersive technology
Package maintainers: 1
CVE-2024-10973
5.7 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): ADJACENT_NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 8 months, 1 week ago
Keycloak: cli option for encrypted jgroups ignored

A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.

keycloak
*
<23.0
<25.0
org.keycloak/keycloak-quarkus-server

pkgs.keycloak

Identity and access management for modern applications and services

pkgs.terraform-providers.keycloak

pkgs.python311Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API
Package maintainers: 3
CVE-2024-0874
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 8 months, 1 week ago
Coredns: cd bit response is cached and served later

A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.

coredns
<1.11.2
openshift4/ose-coredns
*
openshift4/ose-coredns-rhel9
*
rhacm2/lighthouse-agent-rhel8
rhacm2/lighthouse-agent-rhel9
openshift-logging/logging-loki-rhel8
openshift-logging/logging-loki-rhel9
rhacm2-tech-preview/lighthouse-agent-rhel8

pkgs.coredns

DNS server that runs middleware
Package maintainers: 3
CVE-2024-54384
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 8 months, 1 week ago
WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.8.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in eLightUp Falcon – WordPress Optimizations & Tweaks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Falcon – WordPress Optimizations & Tweaks: from n/a through 2.8.3.

falcon
=<2.8.3

pkgs.python311Packages.falcon

Unladen web framework for building APIs and app backends

pkgs.python312Packages.falcon

Unladen web framework for building APIs and app backends
Package maintainers: 2
CVE-2024-54348
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 8 months, 1 week ago
WordPress Brandy theme <= 1.1.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YayCommerce Brand allows Stored XSS.This issue affects Brand: from n/a through 1.1.6.

brand
=<1.1.6

pkgs.matrix-brandy

Matrix Brandy BASIC VI for Linux, Windows, MacOSX

pkgs.librandombytes

A simple API for applications generating fresh randomness

pkgs.librandombytes.x86_64-linux

A simple API for applications generating fresh randomness

pkgs.librandombytes.aarch64-linux

A simple API for applications generating fresh randomness

pkgs.librandombytes.x86_64-darwin

A simple API for applications generating fresh randomness

pkgs.librandombytes.aarch64-darwin

A simple API for applications generating fresh randomness
Package maintainers: 4
CVE-2024-56007
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 8 months, 1 week ago
WordPress Leader plugin <= 2.6.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Ram Segev Leader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leader: from n/a through 2.6.1.

leader
=<2.6.1

pkgs.vimPlugins.vim-leader-guide.x86_64-linux

pkgs.vimPlugins.vim-leader-guide.aarch64-linux

pkgs.vimPlugins.vim-leader-guide.x86_64-darwin

pkgs.vimPlugins.vim-leader-guide.aarch64-darwin

CVE-2024-54368
9.6 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 8 months, 1 week ago
WordPress GitSync plugin <= 1.1.0 - CSRF to Remote Code Execution vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garza, Jr. GitSync allows Code Injection.This issue affects GitSync: from n/a through 1.1.0.

git-sync
=<1.1.0
Package maintainers: 1