Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 356

Количество 25 356

msrc логотип

CVE-2021-45485

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-45480

6 месяцев назад

An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-45469

больше 4 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-45444

больше 4 лет назад

In zsh before 5.8.1 an attacker can achieve code execution if they control a command output inside the prompt as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-45402

больше 4 лет назад

The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction which allows local users to obtain potentially sensitive address information aka a "pointer leak."

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-45095

больше 4 лет назад

pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-45079

больше 4 лет назад

In strongSwan before 5.9.5 a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2021-45078

больше 4 лет назад

stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-44964

больше 4 лет назад

CVSS3: 6.3
EPSS: Низкий
msrc логотип

CVE-2021-44879

больше 4 лет назад

In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3 special files are not considered leading to a move_data_page NULL pointer dereference.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-44790

больше 4 лет назад

Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier

CVSS3: 9.8
EPSS: Критический
msrc логотип

CVE-2021-44758

почти 2 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-44733

больше 4 лет назад

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2021-44732

11 месяцев назад

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

EPSS: Низкий
msrc логотип

CVE-2021-44716

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-44647

больше 4 лет назад

Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-44533

больше 4 лет назад

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-44532

больше 4 лет назад

CVSS3: 5.3
EPSS: Средний
msrc логотип

CVE-2021-44531

больше 4 лет назад

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2021-44269

больше 4 лет назад

An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c tainted variable cnt is too large that makes pointer sptr read beyond heap bound.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 7.5
4%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-45480

An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-45444

In zsh before 5.8.1 an attacker can achieve code execution if they control a command output inside the prompt as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-45402

The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction which allows local users to obtain potentially sensitive address information aka a "pointer leak."

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-45095

pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-45079

In strongSwan before 5.9.5 a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.

CVSS3: 9.1
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-45078

stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 6.3
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-44879

In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3 special files are not considered leading to a move_data_page NULL pointer dereference.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-44790

Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier

CVSS3: 9.8
97%
Критический
больше 4 лет назад
msrc логотип
CVSS3: 7.5
1%
Низкий
почти 2 года назад
msrc логотип
CVSS3: 7
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-44732

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

3%
Низкий
11 месяцев назад
msrc логотип
CVSS3: 7.5
4%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-44647

Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 5.3
9%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 5.3
10%
Средний
больше 4 лет назад
msrc логотип
CVSS3: 7.4
8%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-44269

An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c tainted variable cnt is too large that makes pointer sptr read beyond heap bound.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу