DE EN FR
hlukh.ch Stand: 2026-02-25T15:01:21.749Z · week: 2024-W11

Sicherheitswarnungen

Kuratiert aus öffentlich verfügbaren Advisories. Fokus: Sichtbarkeit, Einordnung und schneller Export – ohne Clickbait.

Neueste Warnungen
CVE-2024-21392
.NET and Visual Studio Denial of Service Vulnerability
2026‑02‑20 · CVE-2024-21392
MSRC 2026‑02‑20 Hoch
CVE-2024-29059
.NET Framework Information Disclosure Vulnerability
2026‑02‑20 · CVE-2024-29059
MSRC 2026‑02‑20 Hoch
CVE-2024-2605
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
2026‑02‑20 · CVE-2024-2605
MSRC 2026‑02‑20 Mittel
CVE-2024-29943
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.
2026‑02‑20 · CVE-2024-29943
MSRC 2026‑02‑20 Kritisch
CVE-2023-52561
arm64: dts: qcom: sdm845-db845c: Mark cont splash memory region as reserved
2026‑02‑20 · CVE-2023-52561
MSRC 2026‑02‑20 Mittel
CVE-2024-29195
Azure C SDK Integer Wraparound Vulnerability
2026‑02‑20 · CVE-2024-29195
MSRC 2026‑02‑20 Mittel
CVE-2024-26203
Azure Data Studio Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-26203
MSRC 2026‑02‑20 Hoch
CVE-2024-21421
Azure SDK Spoofing Vulnerability
2026‑02‑20 · CVE-2024-21421
MSRC 2026‑02‑20 Hoch
CVE-2023-52621
bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers
2026‑02‑20 · CVE-2023-52621
MSRC 2026‑02‑20 Mittel
CVE-2023-52569
btrfs: remove BUG() after failure to insert delayed dir index item
2026‑02‑20 · CVE-2023-52569
MSRC 2026‑02‑20 Mittel
CVE-2023-52572
cifs: Fix UAF in cifs_demultiplex_thread()
2026‑02‑20 · CVE-2023-52572
MSRC 2026‑02‑20 Hoch
CVE-2024-24784
Comments in display names are incorrectly handled in net/mail
2026‑02‑20 · CVE-2024-24784
MSRC 2026‑02‑20 Hoch
CVE-2024-26648
drm/amd/display: Fix variable deferencing before NULL check in edp_setup_replay()
2026‑02‑20 · CVE-2024-26648
MSRC 2026‑02‑20 Mittel
CVE-2023-52625
drm/amd/display: Refactor DMCUB enter/exit idle interface
2026‑02‑20 · CVE-2023-52625
MSRC 2026‑02‑20 Mittel
CVE-2023-52624
drm/amd/display: Wake DMCUB before executing GPINT commands
2026‑02‑20 · CVE-2023-52624
MSRC 2026‑02‑20 Hoch
CVE-2023-52585
drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
2026‑02‑20 · CVE-2023-52585
MSRC 2026‑02‑20 Mittel
CVE-2023-52586
drm/msm/dpu: Add mutex lock in control vblank irq
2026‑02‑20 · CVE-2023-52586
MSRC 2026‑02‑20 Hoch
CVE-2024-24785
Errors returned from JSON marshaling may break template escaping in html/template
2026‑02‑20 · CVE-2024-24785
MSRC 2026‑02‑20 Mittel
CVE-2024-21431
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
2026‑02‑20 · CVE-2024-21431
MSRC 2026‑02‑20 Hoch
CVE-2024-2612
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
2026‑02‑20 · CVE-2024-2612
MSRC 2026‑02‑20 Hoch
CVE-2024-2313
If kernel headers need to be extracted bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.
2026‑02‑20 · CVE-2024-2313
MSRC 2026‑02‑20 Niedrig
CVE-2024-2314
If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.
2026‑02‑20 · CVE-2024-2314
MSRC 2026‑02‑20 Niedrig
CVE-2024-30204
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
2026‑02‑20 · CVE-2024-30204
MSRC 2026‑02‑20 Niedrig
CVE-2024-23722
In Fluent Bit 2.1.8 through 2.2.1 a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.
2026‑02‑20 · CVE-2024-23722
MSRC 2026‑02‑20 Hoch
CVE-2024-30161
In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.)
2026‑02‑20 · CVE-2024-30161
MSRC 2026‑02‑20 Mittel
CVE-2023-45289
Incorrect forwarding of sensitive headers and cookies on HTTP redirect in net/http
2026‑02‑20 · CVE-2023-45289
MSRC 2026‑02‑20 Mittel
CVE-2023-52601
jfs: fix array-index-out-of-bounds in dbAdjTree
2026‑02‑20 · CVE-2023-52601
MSRC 2026‑02‑20 Hoch
CVE-2024-2002
Libdwarf: crashes randomly on fuzzed object
2026‑02‑20 · CVE-2024-2002
MSRC 2026‑02‑20 Hoch
CVE-2024-28757
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
2026‑02‑20 · CVE-2024-28757
MSRC 2026‑02‑20 Hoch
CVE-2024-2496
Libvirt: null pointer dereference in udevconnectlistallinterfaces()
2026‑02‑20 · CVE-2024-2496
MSRC 2026‑02‑20 Mittel
CVE-2023-52589
media: rkisp1: Fix IRQ disable race issue
2026‑02‑20 · CVE-2023-52589
MSRC 2026‑02‑20 Mittel
CVE-2023-45290
Memory exhaustion in multipart form parsing in net/textproto and net/http
2026‑02‑20 · CVE-2023-45290
MSRC 2026‑02‑20 Mittel
CVE-2024-2614
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
2026‑02‑20 · CVE-2024-2614
MSRC 2026‑02‑20 Hoch
CVE-2024-21438
Microsoft AllJoyn API Denial of Service Vulnerability
2026‑02‑20 · CVE-2024-21438
MSRC 2026‑02‑20 Hoch
CVE-2024-21390
Microsoft Authenticator Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21390
MSRC 2026‑02‑20 Hoch
CVE-2024-21400
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-21400
MSRC 2026‑02‑20 Kritisch
CVE-2024-20671
Microsoft Defender Security Feature Bypass Vulnerability
2026‑02‑20 · CVE-2024-20671
MSRC 2026‑02‑20 Mittel
CVE-2024-26164
Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-26164
MSRC 2026‑02‑20 Hoch
CVE-2024-21419
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
2026‑02‑20 · CVE-2024-21419
MSRC 2026‑02‑20 Hoch
CVE-2024-26246
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
2026‑02‑20 · CVE-2024-26246
MSRC 2026‑02‑20 Niedrig
CVE-2024-26163
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
2026‑02‑20 · CVE-2024-26163
MSRC 2026‑02‑20 Mittel
CVE-2024-26247
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
2026‑02‑20 · CVE-2024-26247
MSRC 2026‑02‑20 Mittel
CVE-2024-29057
Microsoft Edge (Chromium-based) Spoofing Vulnerability
2026‑02‑20 · CVE-2024-29057
MSRC 2026‑02‑20 Mittel
CVE-2024-26167
Microsoft Edge for Android Spoofing Vulnerability
2026‑02‑20 · CVE-2024-26167
MSRC 2026‑02‑20 Mittel
CVE-2024-26198
Microsoft Exchange Server Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-26198
MSRC 2026‑02‑20 Hoch
CVE-2024-26201
Microsoft Intune Linux Agent Elevation of Privilege Vulnerability
2026‑02‑20 · CVE-2024-26201
MSRC 2026‑02‑20 Mittel
CVE-2024-21451
Microsoft ODBC Driver Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-21451
MSRC 2026‑02‑20 Hoch
CVE-2024-26159
Microsoft ODBC Driver Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-26159
MSRC 2026‑02‑20 Hoch
CVE-2024-21440
Microsoft ODBC Driver Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-21440
MSRC 2026‑02‑20 Hoch
CVE-2024-26162
Microsoft ODBC Driver Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2024-26162
MSRC 2026‑02‑20 Hoch
Seite 1