Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 768

Количество 18 768

msrc логотип

CVE-2021-31916

больше 4 лет назад

An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2021-31879

больше 4 лет назад

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2021-31829

больше 4 лет назад

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads leading to disclosure of stack content via side-channel attacks aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-3178

около 5 лет назад

fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8 when there is an NFS export of a subdirectory of a filesystem allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavior

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-3177

около 5 лет назад

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2021-31618

9 месяцев назад

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2021-31525

больше 4 лет назад

net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server Transport and Client can each be affected in some configurations.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2021-31214

больше 4 лет назад

Visual Studio Code Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-31213

больше 4 лет назад

Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-31211

больше 4 лет назад

Visual Studio Code Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-31209

больше 4 лет назад

Microsoft Exchange Server Spoofing Vulnerability

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-31208

больше 4 лет назад

Windows Container Manager Service Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-31207

больше 4 лет назад

Microsoft Exchange Server Security Feature Bypass Vulnerability

CVSS3: 6.6
EPSS: Критический
msrc логотип

CVE-2021-31206

больше 4 лет назад

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS3: 7.6
EPSS: Низкий
msrc логотип

CVE-2021-31205

больше 4 лет назад

Windows SMB Client Security Feature Bypass Vulnerability

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-31204

больше 4 лет назад

.NET and Visual Studio Elevation of Privilege Vulnerability

CVSS3: 7.3
EPSS: Низкий
msrc логотип

CVE-2021-31201

больше 4 лет назад

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVSS3: 5.2
EPSS: Низкий
msrc логотип

CVE-2021-31200

больше 4 лет назад

Common Utilities Remote Code Execution Vulnerability

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2021-31199

больше 4 лет назад

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVSS3: 5.2
EPSS: Низкий
msrc логотип

CVE-2021-31198

больше 4 лет назад

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2021-31916

An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 6.1
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31829

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads leading to disclosure of stack content via side-channel attacks aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-3178

fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8 when there is an NFS export of a subdirectory of a filesystem allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavior

CVSS3: 6.5
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-3177

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.

CVSS3: 9.8
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 7.5
19%
Средний
9 месяцев назад
msrc логотип
CVE-2021-31525

net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server Transport and Client can each be affected in some configurations.

CVSS3: 5.9
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31214

Visual Studio Code Remote Code Execution Vulnerability

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31213

Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability

CVSS3: 7.8
5%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31211

Visual Studio Code Remote Code Execution Vulnerability

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31209

Microsoft Exchange Server Spoofing Vulnerability

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31208

Windows Container Manager Service Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31207

Microsoft Exchange Server Security Feature Bypass Vulnerability

CVSS3: 6.6
94%
Критический
больше 4 лет назад
msrc логотип
CVE-2021-31206

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS3: 7.6
9%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31205

Windows SMB Client Security Feature Bypass Vulnerability

CVSS3: 6.5
6%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31204

.NET and Visual Studio Elevation of Privilege Vulnerability

CVSS3: 7.3
9%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31201

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVSS3: 5.2
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31200

Common Utilities Remote Code Execution Vulnerability

CVSS3: 7.2
5%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31199

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVSS3: 5.2
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-31198

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS3: 7.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу