CVE-2025-0337 – ServiceNow Now Platform Authorization Bypass Vulnerability

The following table lists the changes that have been made to the CVE-2025-0337 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 06, 2025 Action […]

CVE-2024-58083 – “KVM Linux Online VCPU Access Control Vulnerability”

In the Linux kernel, the following vulnerability has been resolved: KVM: Explicitly verify target vCPU is online in kvm_get_vcpu() Explicitly verify the target vCPU is fully online _prior_ to clamping the index in kvm_get_vcpu(). If the index is “bad”, the nospec clamping will generate ‘0’, i.e. KVM will return vCPU0 instead of NULL. In practice, […]

CVE-2024-58085 – Linux Tomoyo Overlong Line Allocation Denial of Service

In the Linux kernel, the following vulnerability has been resolved: tomoyo: don’t emit warning in tomoyo_write_control() syzbot is reporting too large allocation warning at tomoyo_write_control(), for one can write a very very long line without new line character. To fix this warning, I use __GFP_NOWARN rather than checking for KMALLOC_MAX_SIZE, for practically a valid line […]

CVE-2024-58084 – Qualcomm QCOM Firmware Read Barrier Vulnerability (Data Corruption)

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix missing read barrier in qcom_scm_get_tzmem_pool() Commit 2e4955167ec5 (“firmware: qcom: scm: Fix __scm and waitq completion variable initialization”) introduced a write barrier in probe function to store global ‘__scm’ variable. We all known barriers are paired (see memory-barriers.txt: “Note that write barriers […]

CVE-2024-58077 – Linux Kernel ASoC soc_pcm Denial-of-Service Vulnerability

The following table lists the changes that have been made to the CVE-2024-58077 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Mar. 06, 2025 Action […]

CVE-2024-58082 – NuvoMedia NULL Pointer Dereference

The following table lists the changes that have been made to the CVE-2024-58082 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Mar. 06, 2025 Action […]

CVE-2024-58081 – Linux Kernel clk MMP2 NULL Pointer Dereference Vulnerability

The following table lists the changes that have been made to the CVE-2024-58081 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Mar. 06, 2025 Action […]

CVE-2024-58079 – Linux UVC Driver GPIO Unbind Crash Vulnerability

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix crash during unbind if gpio unit is in use We used the wrong device for the device managed functions. We used the usb device, when we should be using the interface device. If we unbind the driver from the usb interface, the […]

CVE-2024-58080 – Qualcomm QCOM Dispcc-sm6350 Clock Null Pointer Dereference Vulnerability

The following table lists the changes that have been made to the CVE-2024-58080 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Mar. 06, 2025 Action […]

CVE-2024-58078 – Linux Kernel Misc Dynamic Minor Allocation IDA Free Vulnerability

The following table lists the changes that have been made to the CVE-2024-58078 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Mar. 06, 2025 Action […]