All CVEs — page 220 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows unauthenticated access to the token endpoint of Apache Airflow Keycloak provider, enabling attackers to obtain session tokens for any registered client in the Keycloak realm, posing a significant security risk.
The flaw allows an attacker to pair a valid Airflow session token with another user's Keycloak access or refresh token, granting unauthorized access and privileges.
An unauthenticated attacker can exploit a flaw in Arista EOS P4Runtime to achieve arbitrary code execution, granting full administrative control over the switch.
This flaw involves a use-after-free vulnerability in the Linux kernel's ksmbd module, where a concurrent session logoff can free a tree connection object while it is still being used by a handler, leading to potential kernel crashes or exploits.
This vulnerability in the ext4 file system of the Linux kernel allows an attacker to trigger a slab-out-of-bounds read, potentially leading to information disclosure.