Количество 25 356
Количество 25 356
CVE-2021-4190
CVE-2021-4187
CVE-2021-4186
CVE-2021-41864
prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.
CVE-2021-4185
CVE-2021-4184
CVE-2021-4182
CVE-2021-4181
CVE-2021-41819
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
CVE-2021-41817
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1 3.1.2 3.0.2 and 2.0.1.
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
CVE-2021-41772
CVE-2021-41771
CVE-2021-4173
CVE-2021-4166
CVE-2021-41617
sshd in OpenSSH 6.2 through 8.x before 8.8 when certain non-default configurations are used allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process if the configuration specifies running the command as a different user.
CVE-2021-4160
CVE-2021-4158
CVE-2021-4157
An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user having access to the NFS mount could potentially use this flaw to crash the system or escalate privileges on the system.
CVE-2021-4155
A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | ||
CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | ||
CVE-2021-41864 prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write. | CVSS3: 7.8 | 0% Низкий | почти 5 лет назад | |
CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | ||
CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | ||
CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | ||
CVE-2021-41819 CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
CVE-2021-41817 Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1 3.1.2 3.0.2 and 2.0.1. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
CVE-2021-41773 Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 | CVSS3: 7.5 | 100% Критический | почти 5 лет назад | |
CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | ||
CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | ||
CVSS3: 7.1 | 2% Низкий | больше 4 лет назад | ||
CVE-2021-41617 sshd in OpenSSH 6.2 through 8.x before 8.8 when certain non-default configurations are used allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process if the configuration specifies running the command as a different user. | CVSS3: 7 | 3% Низкий | почти 5 лет назад | |
CVSS3: 5.9 | 4% Низкий | больше 4 лет назад | ||
CVSS3: 6 | 0% Низкий | почти 2 года назад | ||
CVE-2021-4157 An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user having access to the NFS mount could potentially use this flaw to crash the system or escalate privileges on the system. | CVSS3: 8 | 2% Низкий | больше 4 лет назад | |
CVE-2021-4155 A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу