A vulnerability classified as critical has been found in Oracle Retail Xstore Point of Service 16.0.6/17.0.4/18.0.3/19.0.2/20.0.1 (Warehouse Management System Software). Affected is an unknown code block of the component Node.js. Upgrading eliminates this vulnerability. A possible mitigation has been published immediately after the disclosure of the vulnerability.
Oracle Retail Xstore Point of Service 16.0.6/17.0.4/18.0.3/19.0.2/20.0.1 Node.js denial of service
- Virtual Patching
- July 21, 2021
- 9:05 am
CVE-2024-24856 : LINUX KERNEL UP TO 6.8 ACPI_ALLOCATE_ZEROED NULL POINTER DEREFERENCE
Description The memory allocation function ACPI_ALLOCATE_ZEROED does not guarantee a successful allocation, but the subsequent code directly dereferences the pointer
CVE-2024-2912 : BENTOML FRAMEWORK UP TO 1.2.4 POST REQUEST INSECURE DEFAULT INITIALIZATION OF RESOURCE
Description An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted
CVE-2024-26817 : LINUX KERNEL UP TO 6.8.5 AMDKFD KZALLOC INTEGER OVERFLOW
Description In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer