DE EN FR
hlukh.ch MàJ : 2026-02-25T09:01:16.562Z · week: 2024-W07

Alertes de sécurité

Sélectionnées à partir d'avis publics. Objectif : visibilité, contexte et export rapide — sans clickbait.

Alertes récentes
CVE-2024-24577
libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`
2026‑02‑20 · CVE-2024-24577
MSRC 2026‑02‑20 Critique
CVE-2024-21403
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21403
MSRC 2026‑02‑20 Critique
CVE-2024-21376
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-21376
MSRC 2026‑02‑20 Critique
CVE-2024-21364
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21364
MSRC 2026‑02‑20 Critique
CVE-2024-21401
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21401
MSRC 2026‑02‑20 Critique
CVE-2024-21410
Microsoft Exchange Server Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21410
MSRC 2026‑02‑20 Critique
CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-21413
MSRC 2026‑02‑20 Critique
CVE-2024-21896
The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals namely Buffer.prototype.utf8Write the application can modify the result of path.resolve() which leads to a path traversal vulnerability. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js.
2026‑02‑20 · CVE-2024-21896
MSRC 2026‑02‑20 Critique
CVE-2024-27319
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
2026‑02‑20 · CVE-2024-27319
MSRC 2026‑02‑20 Critique
CVE-2020-3259
Cisco ASA and FTD Information Disclosure Vulnerability
2024‑02‑15 · CVE-2020-3259
CISA-KEV 2024‑02‑15 Critique
CVE-2024-21412
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
2024‑02‑13 · CVE-2024-21412
CISA-KEV 2024‑02‑13 Critique
Page 1