NVD disclosure day

Published threat advisories for November 21, 2024

CVE advisoryCRITICAL

CVE-2024-51366

OmegaT Arbitrary File Upload Leading to Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An arbitrary file upload flaw in OmegaT's file handling could allow attackers to execute arbitrary code by uploading a crafted configuration file. While OmegaT is a local translation tool not typically internet-facing, this vulnerability, if reachable, presents a risk of code execution. Confirming its relevance and pot

CVE advisoryCRITICAL

CVE-2024-53095

Linux Kernel CIFS Use-After-Free in Network Namespace Handling

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Linux kernel has a use-after-free vulnerability in its CIFS client when handling network namespaces. This flaw could lead to system instability or crashes, particularly in containerized environments like Kubernetes, if pods using CIFS mounts are terminated under specific conditions. Readers should care because this