CVE-2024-8354 – Qemu-kvm: usb: assertion failure in usb_ep_get()
https://notcve.org/view.php?id=CVE-2024-8354
19 Sep 2024 — This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition. • https://access.redhat.com/security/cve/CVE-2024-8354 • CWE-617: Reachable Assertion •
CVE-2024-45813 – ReDoS vulnerability in multiparametric routes in find-my-way
https://notcve.org/view.php?id=CVE-2024-45813
18 Sep 2024 — This may cause a denial of service in some instances. ... A regular expression denial of service (ReDoS) flaw was found in find-my-way. ... This issue may cause a denial of service in some instances. • https://blakeembrey.com/posts/2024-09-web-redos • CWE-1333: Inefficient Regular Expression Complexity •
CVE-2024-36981
https://notcve.org/view.php?id=CVE-2024-36981
18 Sep 2024 — A specially crafted network request can lead to denial of service. • https://talosintelligence.com/vulnerability_reports/TALOS-2024-2004 • CWE-125: Out-of-bounds Read •
CVE-2024-36980
https://notcve.org/view.php?id=CVE-2024-36980
18 Sep 2024 — A specially crafted network request can lead to denial of service. • https://talosintelligence.com/vulnerability_reports/TALOS-2024-2004 • CWE-125: Out-of-bounds Read •
CVE-2024-39590
https://notcve.org/view.php?id=CVE-2024-39590
18 Sep 2024 — A specially crafted EtherNet/IP request can lead to denial of service. • https://talosintelligence.com/vulnerability_reports/TALOS-2024-2016 • CWE-704: Incorrect Type Conversion or Cast •
CVE-2024-39589
https://notcve.org/view.php?id=CVE-2024-39589
18 Sep 2024 — A specially crafted EtherNet/IP request can lead to denial of service. • https://talosintelligence.com/vulnerability_reports/TALOS-2024-2016 • CWE-704: Incorrect Type Conversion or Cast •
CVE-2024-8887 – Authentication bypass vulnerability on CIRCUTOR Q-SMT
https://notcve.org/view.php?id=CVE-2024-8887
18 Sep 2024 — CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all the functionalities implemented at web level that allow interacting with the device. • https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products • CWE-1284: Improper Validation of Specified Quantity in Input •
CVE-2024-46800 – sch/netem: fix use after free in netem_dequeue
https://notcve.org/view.php?id=CVE-2024-46800
18 Sep 2024 — A physically proximate remote attacker could use this to cause a denial of service or possibly execute arbitrary code. • https://git.kernel.org/stable/c/50612537e9ab29693122fab20fc1eed235054ffe •
CVE-2024-46798 – ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object
https://notcve.org/view.php?id=CVE-2024-46798
18 Sep 2024 — A physically proximate remote attacker could use this to cause a denial of service or possibly execute arbitrary code. • https://git.kernel.org/stable/c/a72706ed8208ac3f72d1c3ebbc6509e368b0dcb0 •
CVE-2024-46797 – powerpc/qspinlock: Fix deadlock in MCS queue
https://notcve.org/view.php?id=CVE-2024-46797
18 Sep 2024 — A local attacker could possibly use this to cause a denial of service. • https://git.kernel.org/stable/c/84990b169557428c318df87b7836cd15f65b62dc •