Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 769

Количество 18 769

msrc логотип

CVE-2021-28972

почти 5 лет назад

In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8 the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination aka CID-cc7a0bb058b8.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2021-28971

почти 5 лет назад

In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled aka CID-d88d05a9e0b6.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-28965

почти 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-28964

почти 5 лет назад

A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation aka CID-dbcc7d57bffc.

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2021-28957

больше 4 лет назад

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2021-28952

почти 5 лет назад

An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-28951

почти 5 лет назад

An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread but concurrently that SQPOLL thread is waiting for a signal to start aka CID-3ebba796fa25.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-28950

почти 5 лет назад

An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode aka CID-775c5033a0d1.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-28879

почти 5 лет назад

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2021-28878

почти 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-28877

почти 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-28876

почти 5 лет назад

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-28875

почти 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-28861

больше 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2021-28831

почти 5 лет назад

decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer with a resultant invalid free or segmentation fault via malformed gzip data.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-28715

около 4 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-28714

около 4 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-28691

больше 4 лет назад

Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-28660

почти 5 лет назад

rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases CVE IDs are not normally used for drivers/staging/* (unfinished work); however system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2021-28544

почти 4 года назад

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2021-28972

In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8 the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination aka CID-cc7a0bb058b8.

CVSS3: 6.7
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-28971

In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled aka CID-d88d05a9e0b6.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-28964

A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation aka CID-dbcc7d57bffc.

CVSS3: 4.7
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-28957

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-28952

An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)

CVSS3: 7.8
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-28951

An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread but concurrently that SQPOLL thread is waiting for a signal to start aka CID-3ebba796fa25.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-28950

An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode aka CID-775c5033a0d1.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 9.8
1%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 7.5
1%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 5.3
0%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2021-28831

decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer with a resultant invalid free or segmentation fault via malformed gzip data.

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 6.5
0%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 6.5
0%
Низкий
около 4 лет назад
msrc логотип
CVE-2021-28691

Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-28660

rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases CVE IDs are not normally used for drivers/staging/* (unfinished work); however system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.

CVSS3: 8.8
0%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 4.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу