Логотип exploitDog
bind:"CVE-2021-35937" OR bind:"CVE-2021-35938" OR bind:"CVE-2021-35939"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-35937" OR bind:"CVE-2021-35938" OR bind:"CVE-2021-35939"

Количество 25

Количество 25

rocky логотип

RLSA-2024:0647

почти 2 года назад

Moderate: rpm security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0647

почти 2 года назад

ELSA-2024-0647: rpm security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0463

почти 2 года назад

ELSA-2024-0463: rpm security update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20240410-21

больше 1 года назад

Множественные уязвимости rpm

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-35937

около 3 лет назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2021-35937

больше 4 лет назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2021-35937

около 3 лет назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2021-35937

около 3 лет назад

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2021-35937

около 3 лет назад

A race condition vulnerability was found in rpm. A local unprivileged ...

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-63x9-9q4w-j636

около 3 лет назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
EPSS: Низкий
fstec логотип

BDU:2021-03555

больше 4 лет назад

Уязвимость менеджера RPM-пакетов RPM (RPM Package Manager) операционных систем Red Hat Enterprise Linux, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2021-35939

около 3 лет назад

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2021-35939

больше 4 лет назад

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-35939

около 3 лет назад

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2021-35939

около 3 лет назад

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2021-35939

около 3 лет назад

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was inco ...

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2021-35938

около 3 лет назад

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2021-35938

больше 4 лет назад

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-35938

около 3 лет назад

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2021-35938

около 3 лет назад

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:0647

Moderate: rpm security update

почти 2 года назад
oracle-oval логотип
ELSA-2024-0647

ELSA-2024-0647: rpm security update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2024-0463

ELSA-2024-0463: rpm security update (MODERATE)

почти 2 года назад
redos логотип
ROS-20240410-21

Множественные уязвимости rpm

CVSS3: 6.5
больше 1 года назад
ubuntu логотип
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 6.4
0%
Низкий
около 3 лет назад
debian логотип
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged ...

CVSS3: 6.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-63x9-9q4w-j636

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2021-03555

Уязвимость менеджера RPM-пакетов RPM (RPM Package Manager) операционных систем Red Hat Enterprise Linux, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 6.7
0%
Низкий
около 3 лет назад
debian логотип
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was inco ...

CVSS3: 6.7
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2021-35938

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2021-35938

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-35938

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2021-35938

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
около 3 лет назад

Уязвимостей на страницу