Количество 25 356
Количество 25 356
CVE-2021-42279
Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2021-42278
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42277
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
CVE-2021-42276
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-42275
Microsoft COM for Windows Remote Code Execution Vulnerability
CVE-2021-42274
Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
CVE-2021-42252
An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.
CVE-2021-42248
CVE-2021-4217
The vulnerability in unzip occurs due to improper handling of Unicode strings
CVE-2021-4209
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.
CVE-2021-4207
CVE-2021-4206
CVE-2021-4203
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw an attacker with a user privileges may crash the system or leak internal kernel information.
CVE-2021-4202
A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed leading to a privilege escalation problem.
CVE-2021-42008
The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.
CVE-2021-41991
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator but this is not done correctly. Remote code execution might be a slight possibility.
CVE-2021-41990
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
CVE-2021-4197
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.
CVE-2021-4193
CVE-2021-4192
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-42279 Chakra Scripting Engine Memory Corruption Vulnerability | CVSS3: 4.2 | 2% Низкий | почти 5 лет назад | |
CVE-2021-42278 Active Directory Domain Services Elevation of Privilege Vulnerability | CVSS3: 7.5 | 70% Высокий | почти 5 лет назад | |
CVE-2021-42277 Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | CVSS3: 5.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-42276 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | CVSS3: 7.8 | 2% Низкий | почти 5 лет назад | |
CVE-2021-42275 Microsoft COM for Windows Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | почти 5 лет назад | |
CVE-2021-42274 Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability | CVSS3: 6.8 | 1% Низкий | почти 5 лет назад | |
CVE-2021-42252 An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes. | CVSS3: 7.8 | 0% Низкий | почти 5 лет назад | |
| почти 2 года назад | ||||
CVE-2021-4217 The vulnerability in unzip occurs due to improper handling of Unicode strings | CVSS3: 3.3 | 1% Низкий | больше 1 года назад | |
CVE-2021-4209 A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
CVSS3: 8.2 | 0% Низкий | почти 2 года назад | ||
CVSS3: 8.2 | 1% Низкий | около 2 лет назад | ||
CVE-2021-4203 A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw an attacker with a user privileges may crash the system or leak internal kernel information. | CVSS3: 6.8 | 2% Низкий | больше 4 лет назад | |
CVE-2021-4202 A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed leading to a privilege escalation problem. | CVSS3: 7 | 0% Низкий | больше 4 лет назад | |
CVE-2021-42008 The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access. | CVSS3: 7.8 | 2% Низкий | почти 5 лет назад | |
CVE-2021-41991 The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator but this is not done correctly. Remote code execution might be a slight possibility. | CVSS3: 7.5 | 5% Низкий | почти 5 лет назад | |
CVE-2021-41990 The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. | CVSS3: 7.5 | 6% Низкий | почти 5 лет назад | |
CVE-2021-4197 An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | ||
CVSS3: 7.8 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу