Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 824

Количество 18 824

msrc логотип

CVE-2021-4217

10 месяцев назад

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2021-4209

больше 3 лет назад

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-4207

больше 1 года назад

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2021-4206

больше 1 года назад

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2021-4203

почти 4 года назад

A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw an attacker with a user privileges may crash the system or leak internal kernel information.

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2021-4202

почти 4 года назад

A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed leading to a privilege escalation problem.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2021-42008

больше 4 лет назад

The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-41991

больше 4 лет назад

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator but this is not done correctly. Remote code execution might be a slight possibility.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-41990

больше 4 лет назад

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-4197

почти 4 года назад

An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-4193

около 4 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-4192

около 4 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-4190

почти 4 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-4187

около 4 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-4186

около 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-41864

больше 4 лет назад

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-4185

около 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-4184

около 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-4182

около 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-4181

около 4 лет назад

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 3.3
0%
Низкий
10 месяцев назад
msrc логотип
CVE-2021-4209

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 8.2
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 8.2
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2021-4203

A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw an attacker with a user privileges may crash the system or leak internal kernel information.

CVSS3: 6.8
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-4202

A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed leading to a privilege escalation problem.

CVSS3: 7
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-42008

The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-41991

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator but this is not done correctly. Remote code execution might be a slight possibility.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-41990

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-4197

An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 5.5
1%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 7.8
1%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 7.8
0%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
около 4 лет назад
msrc логотип
CVE-2021-41864

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу