CVE-2024-47969
https://notcve.org/view.php?id=CVE-2024-47969
07 Oct 2024 — Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service. • https://www.solidigm.com/support-page/support-security.html • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2024-47968
https://notcve.org/view.php?id=CVE-2024-47968
07 Oct 2024 — Improper resource shutdown in middle of certain operations on some Solidigm DC Products may allow an attacker to potentially enable denial of service. • https://https://www.solidigm.com/support-page/support-security.html • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2024-47967
https://notcve.org/view.php?id=CVE-2024-47967
07 Oct 2024 — Improper resource initialization handling in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service. • https://https://www.solidigm.com/support-page/support-security.html • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2024-47974
https://notcve.org/view.php?id=CVE-2024-47974
07 Oct 2024 — Race condition during resource shutdown in some Solidigm DC Products may allow an attacker to potentially enable denial of service. • https://https://www.solidigm.com/support-page/support-security.html • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2024-43789 – Denial of service by the absence of restrictions on replies to posts in Discourse
https://notcve.org/view.php?id=CVE-2024-43789
07 Oct 2024 — Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of Discourse. All users area are advised to upgrade. • https://github.com/discourse/discourse/security/advisories/GHSA-62cq-cpmc-hvqq • CWE-400: Uncontrolled Resource Consumption •
CVE-2024-31228 – Denial-of-service due to unbounded pattern matching in Redis
https://notcve.org/view.php?id=CVE-2024-31228
07 Oct 2024 — Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns on supported commands such as `KEYS`, `SCAN`, `PSUBSCRIBE`, `FUNCTION LIST`, `COMMAND LIST` and ACL definitions. ... This flaw allows authenticated users to trigger a denial of service by using specially crafted, long string match patterns on supported commands such as `KEYS`, `SCAN`, `PSUBSCRIBE`, `FUNCTION LIST`, `COMMAND LIST`, and ACL definitions. • https://github.com/redis/redis/commit/9317bf64659b33166a943ec03d5d9b954e86afb0 • CWE-674: Uncontrolled Recursion •
CVE-2024-31227 – Denial-of-service due to malformed ACL selectors in Redis
https://notcve.org/view.php?id=CVE-2024-31227
07 Oct 2024 — An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. ... This flaw allows an authenticated attacker with sufficient privileges to create a malformed ACL selector that triggers a server panic and subsequent denial of service when accessed. • https://github.com/redis/redis/commit/b351d5a3210e61cc3b22ba38a723d6da8f3c298a • CWE-20: Improper Input Validation •
CVE-2024-47971
https://notcve.org/view.php?id=CVE-2024-47971
07 Oct 2024 — Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service. • https://www.solidigm.com/support-page/support-security.html •
CVE-2024-47975
https://notcve.org/view.php?id=CVE-2024-47975
07 Oct 2024 — Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker with local access to potentially enable denial of service. • https://https://www.solidigm.com/support-page/support-security.html •
CVE-2024-38397 – Buffer Over-read in WLAN Host Communication
https://notcve.org/view.php?id=CVE-2024-38397
07 Oct 2024 — Transient DOS while parsing probe response and assoc response frame. • https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html • CWE-126: Buffer Over-read •