PHP is vulnerable to the Marvin Attack
Chromium: CVE-2024-6293 Use after free in Dawn
Argument Injection in PHP-CGI
Filter bypass in filtervar (FILTERVALIDATEURL)
Command injection via array-ish $command parameter of procopen() (bypass CVE-2024-1874 fix)
Chromium: CVE-2024-5499 Out of bounds write in Streams API
Chromium: CVE-2024-5497 Out of bounds memory access in Keyboard Inputs
Chromium: CVE-2024-5493 Heap buffer overflow in WebRTC
Chromium: CVE-2024-5834 Inappropriate implementation in Dawn
Chromium: CVE-2024-5830 Type Confusion in V8
Chromium: CVE-2024-5833 Type Confusion in V8
Chromium: CVE-2024-5838 Type Confusion in V8
Chromium: CVE-2024-6292 Use after free in Dawn
Chromium: CVE-2024-5837 Type Confusion in V8
Chromium: CVE-2024-6290 Use after free in Dawn
Chromium: CVE-2024-5158 Type Confusion in V8
Chromium: CVE-2024-5835 Heap buffer overflow in Tab Groups
Chromium: CVE-2024-5836 Inappropriate Implementation in DevTools
btrfs: make sure that WRITTEN is set on all metadata blocks
Chromium: CVE-2024-5274 Type Confusion in V8
In the Linux kernel, the following vulnerability has been resolved:
dyndbg: fix old BUGON in >control parser
Fix a BUGON from 2009. Even if it looks "unreachable" (I didn't really look), lets make sure by removing it, doing prerr and return -EINVAL instead.
Chromium: CVE-2024-5847 Use after free in PDFium
Chromium: CVE-2024-5846 Use after free in PDFium
Chromium: CVE-2024-4761 Out of bounds write in V8
Use after free issue in editcap could cause denial of service via crafted capture file
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
Memory handling issue in editcap could cause denial of service via crafted capture file
An attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation.
Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at will
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the objects/ directory. Cloning a local repository over the filesystem may creating hardlinks to arbitrary user-owned files on the same filesystem in the target Git repository's objects/ directory. When cloning a repository over the filesystem (without explicitly specifying the file:// protocol or --no-local), the optimizations for local cloning will be used, which include attempting to hard link the object files instead of copying them. While the code includes checks against symbolic links in the source repository, which were added during the fix for CVE-2022-39253, these checks can still be raced because the hard link operation ultimately follows symlinks. If the object on the filesystem appears as a file during the check, and then a symlink during the operation, this will allow the adversary to bypass the check and create hardlinks in the destination objects directory to arbitrary, user-readable files. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.