Database/Control plane, storage & DevOps
Intel Neural Compressor (SQL injection, second instance): A second SQL-injection path in Neural Compressor reachable
CVSS 7.0CVE-2024-39766Control plane, storage & DevOpscurated
Impact
A second SQL-injection path in Neural Compressor reachable by an authenticated user. Same consequence as the first: control of the service's backing store.
Who can reach it
Any authenticated user of the service.
What to do
Upgrade to v3.0 or later. Userspace, restart only.
References
Related entries
- Redis: Authenticated user triggers a stack/heap out-of-bounds write in hyperloglog opsCVE-2025-32023 · RedisHigh
- Sidero Omni: SAML assertion replay race lets a captured saml-session token be redeemed more than onceCVE-2026-45720 · Sidero Omni (SAML session interceptor, internal/pkg/auth/interceptor/saml.go)High
- Redis (multi-bulk command protocol handling): PERMANENT, VENDOR-ACKNOWLEDGED DENIAL OF SERVICE WITH NO FIX PLANNED. AnNCVD-2025-021-redis-multi-bulk-command-protoco · Redis (multi-bulk command protocol handling)High
- AMD AGESA bootloader - DDR5 PMIC default configuration: The AGESA bootloader leaves DDR5 memory modules in an insecureCVE-2025-48516 · AMD AGESA bootloader - DDR5 PMIC default configurationMedium
- AMD Graphics Driver - out-of-bounds write: Improper input validation lets a local attacker write out of bounds throughCVE-2025-48518 · AMD Graphics Driver - out-of-bounds writeMedium
- Terragrunt: malicious module manifest deletes files outside the module cache during cleanupCVE-2026-45099 · Terragrunt (module cache cleanup, .terragrunt-module-manifest path handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.