Количество 18 769
Количество 18 769
CVE-2021-27053
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-27052
Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2021-27051
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27050
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27049
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27048
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-27047
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-26937
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
CVE-2021-26934
An issue was discovered in the Linux kernel 4.18 through 5.10.16 as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration but this wasn't stated accordingly in its support status entry.
CVE-2021-26932
An issue was discovered in the Linux kernel 3.2 through 5.10.16 as used by Xen. Grant mapping operations often occur in batch hypercalls where a number of operations are done in a single hypercall the success or failure of each one is reported to the backend driver and the backend driver then loops over the results performing follow-up actions based on the success or failure of each operation. Unfortunately when running in PV mode the Linux backend drivers mishandle this: Some errors are ignored effectively implying their success from the success of related batch elements. In other cases errors resulting from one batch element lead to further batch elements not being inspected and hence successful ones to not be possible to properly unmap upon error recovery. Only systems with Linux backends running in PV mode are vulnerable. Linux backends run in HVM / PVH modes are not vulnerable. This affects arch/*/xen/p2m.c and drivers/xen/gntdev.c.
CVE-2021-26931
An issue was discovered in the Linux kernel 2.6.39 through 5.10.16 as used in Xen. Block net and SCSI backends consider certain errors a plain bug deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory conditions) it isn't correct to assume a plain bug. Memory allocations potentially causing such crashes occur only when Linux is running in PV mode though. This affects drivers/block/xen-blkback/blkback.c and drivers/xen/xen-scsiback.c.
CVE-2021-26930
An issue was discovered in the Linux kernel 3.11 through 5.10.16 as used by Xen. To service requests to the PV backend the driver maps grant references provided by the frontend. In this process errors may be encountered. In one case an error encountered earlier might be discarded by later processing resulting in the caller assuming successful mapping and hence subsequent operations trying to access space that wasn't mapped. In another case internal state would be insufficiently updated preventing safe recovery from the error. This affects drivers/block/xen-blkback/blkback.c.
CVE-2021-26927
A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.
CVE-2021-26926
A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.
CVE-2021-26902
HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-26901
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-26900
Windows Win32k Elevation of Privilege Vulnerability
CVE-2021-26899
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2021-26898
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-26897
Windows DNS Server Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-27053 Microsoft Excel Remote Code Execution Vulnerability | CVSS3: 7.8 | 4% Низкий | почти 5 лет назад | |
CVE-2021-27052 Microsoft SharePoint Server Information Disclosure Vulnerability | CVSS3: 5.3 | 12% Средний | почти 5 лет назад | |
CVE-2021-27051 HEVC Video Extensions Remote Code Execution Vulnerability | 3% Низкий | почти 5 лет назад | ||
CVE-2021-27050 HEVC Video Extensions Remote Code Execution Vulnerability | 10% Средний | почти 5 лет назад | ||
CVE-2021-27049 HEVC Video Extensions Remote Code Execution Vulnerability | 3% Низкий | почти 5 лет назад | ||
CVE-2021-27048 HEVC Video Extensions Remote Code Execution Vulnerability | 3% Низкий | почти 5 лет назад | ||
CVE-2021-27047 HEVC Video Extensions Remote Code Execution Vulnerability | 10% Средний | почти 5 лет назад | ||
CVE-2021-26937 encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence. | CVSS3: 9.8 | 13% Средний | около 4 лет назад | |
CVE-2021-26934 An issue was discovered in the Linux kernel 4.18 through 5.10.16 as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration but this wasn't stated accordingly in its support status entry. | CVSS3: 7.8 | 0% Низкий | почти 5 лет назад | |
CVE-2021-26932 An issue was discovered in the Linux kernel 3.2 through 5.10.16 as used by Xen. Grant mapping operations often occur in batch hypercalls where a number of operations are done in a single hypercall the success or failure of each one is reported to the backend driver and the backend driver then loops over the results performing follow-up actions based on the success or failure of each operation. Unfortunately when running in PV mode the Linux backend drivers mishandle this: Some errors are ignored effectively implying their success from the success of related batch elements. In other cases errors resulting from one batch element lead to further batch elements not being inspected and hence successful ones to not be possible to properly unmap upon error recovery. Only systems with Linux backends running in PV mode are vulnerable. Linux backends run in HVM / PVH modes are not vulnerable. This affects arch/*/xen/p2m.c and drivers/xen/gntdev.c. | CVSS3: 5.5 | 0% Низкий | почти 5 лет назад | |
CVE-2021-26931 An issue was discovered in the Linux kernel 2.6.39 through 5.10.16 as used in Xen. Block net and SCSI backends consider certain errors a plain bug deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory conditions) it isn't correct to assume a plain bug. Memory allocations potentially causing such crashes occur only when Linux is running in PV mode though. This affects drivers/block/xen-blkback/blkback.c and drivers/xen/xen-scsiback.c. | CVSS3: 5.5 | 0% Низкий | почти 5 лет назад | |
CVE-2021-26930 An issue was discovered in the Linux kernel 3.11 through 5.10.16 as used by Xen. To service requests to the PV backend the driver maps grant references provided by the frontend. In this process errors may be encountered. In one case an error encountered earlier might be discarded by later processing resulting in the caller assuming successful mapping and hence subsequent operations trying to access space that wasn't mapped. In another case internal state would be insufficiently updated preventing safe recovery from the error. This affects drivers/block/xen-blkback/blkback.c. | CVSS3: 7.8 | 0% Низкий | почти 5 лет назад | |
CVE-2021-26927 A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
CVE-2021-26926 A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash. | CVSS3: 7.1 | 0% Низкий | около 4 лет назад | |
CVE-2021-26902 HEVC Video Extensions Remote Code Execution Vulnerability | 10% Средний | почти 5 лет назад | ||
CVE-2021-26901 Windows Event Tracing Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 5 лет назад | |
CVE-2021-26900 Windows Win32k Elevation of Privilege Vulnerability | CVSS3: 7.8 | 5% Низкий | почти 5 лет назад | |
CVE-2021-26899 Windows UPnP Device Host Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | почти 5 лет назад | |
CVE-2021-26898 Windows Event Tracing Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 5 лет назад | |
CVE-2021-26897 Windows DNS Server Remote Code Execution Vulnerability | CVSS3: 9.8 | 11% Средний | почти 5 лет назад |
Уязвимостей на страницу