Количество 18 768
Количество 18 768
CVE-2021-31916
An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
CVE-2021-31879
CVE-2021-31829
kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads leading to disclosure of stack content via side-channel attacks aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.
CVE-2021-3178
fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8 when there is an NFS export of a subdirectory of a filesystem allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavior
CVE-2021-3177
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
CVE-2021-31618
CVE-2021-31525
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server Transport and Client can each be affected in some configurations.
CVE-2021-31214
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-31213
Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability
CVE-2021-31211
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-31209
Microsoft Exchange Server Spoofing Vulnerability
CVE-2021-31208
Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2021-31207
Microsoft Exchange Server Security Feature Bypass Vulnerability
CVE-2021-31206
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-31205
Windows SMB Client Security Feature Bypass Vulnerability
CVE-2021-31204
.NET and Visual Studio Elevation of Privilege Vulnerability
CVE-2021-31201
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
CVE-2021-31200
Common Utilities Remote Code Execution Vulnerability
CVE-2021-31199
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
CVE-2021-31198
Microsoft Exchange Server Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-31916 An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. | CVSS3: 6.7 | 0% Низкий | больше 4 лет назад | |
CVSS3: 6.1 | 0% Низкий | больше 4 лет назад | ||
CVE-2021-31829 kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads leading to disclosure of stack content via side-channel attacks aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-3178 fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8 when there is an NFS export of a subdirectory of a filesystem allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavior | CVSS3: 6.5 | 0% Низкий | около 5 лет назад | |
CVE-2021-3177 Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely. | CVSS3: 9.8 | 0% Низкий | около 5 лет назад | |
CVSS3: 7.5 | 19% Средний | 9 месяцев назад | ||
CVE-2021-31525 net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server Transport and Client can each be affected in some configurations. | CVSS3: 5.9 | 0% Низкий | больше 4 лет назад | |
CVE-2021-31214 Visual Studio Code Remote Code Execution Vulnerability | CVSS3: 7.8 | 4% Низкий | больше 4 лет назад | |
CVE-2021-31213 Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability | CVSS3: 7.8 | 5% Низкий | больше 4 лет назад | |
CVE-2021-31211 Visual Studio Code Remote Code Execution Vulnerability | CVSS3: 7.8 | 4% Низкий | больше 4 лет назад | |
CVE-2021-31209 Microsoft Exchange Server Spoofing Vulnerability | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-31208 Windows Container Manager Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-31207 Microsoft Exchange Server Security Feature Bypass Vulnerability | CVSS3: 6.6 | 94% Критический | больше 4 лет назад | |
CVE-2021-31206 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 7.6 | 9% Низкий | больше 4 лет назад | |
CVE-2021-31205 Windows SMB Client Security Feature Bypass Vulnerability | CVSS3: 6.5 | 6% Низкий | больше 4 лет назад | |
CVE-2021-31204 .NET and Visual Studio Elevation of Privilege Vulnerability | CVSS3: 7.3 | 9% Низкий | больше 4 лет назад | |
CVE-2021-31201 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | CVSS3: 5.2 | 2% Низкий | больше 4 лет назад | |
CVE-2021-31200 Common Utilities Remote Code Execution Vulnerability | CVSS3: 7.2 | 5% Низкий | больше 4 лет назад | |
CVE-2021-31199 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | CVSS3: 5.2 | 1% Низкий | больше 4 лет назад | |
CVE-2021-31198 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу