Количество 25 356
Количество 25 356
CVE-2021-4154
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.
CVE-2021-41524
null pointer dereference in h2 fuzzing
CVE-2021-4150
A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails when adding a partition to the disk.
CVE-2021-41500
Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.
CVE-2021-4149
A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.
CVE-2021-41496
Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19 which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally)
CVE-2021-41495
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing an error can only occur due to an exhaustion of memory. If the user can exhaust memory they are already privileged. Further it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place
CVE-2021-4148
A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.
CVE-2021-4145
CVE-2021-41379
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-41378
Windows NTFS Remote Code Execution Vulnerability
CVE-2021-41377
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
CVE-2021-41376
Azure Sphere Information Disclosure Vulnerability
CVE-2021-41375
Azure Sphere Information Disclosure Vulnerability
CVE-2021-41374
Azure Sphere Information Disclosure Vulnerability
CVE-2021-41373
FSLogix Information Disclosure Vulnerability
CVE-2021-41372
Power BI Report Server Spoofing Vulnerability
CVE-2021-41371
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2021-41370
NTFS Elevation of Privilege Vulnerability
CVE-2021-4136
Heap-based Buffer Overflow in vim/vim
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-4154 A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-41524 null pointer dereference in h2 fuzzing | CVSS3: 7.5 | 25% Средний | почти 5 лет назад | |
CVE-2021-4150 A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails when adding a partition to the disk. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-41500 Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects. | 1% Низкий | 11 месяцев назад | ||
CVE-2021-4149 A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-41496 Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19 which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerability; the negative dimensions can only be created by an already privileged user (or internally) | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-41495 Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing an error can only occur due to an exhaustion of memory. If the user can exhaust memory they are already privileged. Further it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
CVE-2021-4148 A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
0% Низкий | больше 3 лет назад | |||
CVE-2021-41379 Windows Installer Elevation of Privilege Vulnerability | CVSS3: 5.5 | 20% Средний | почти 5 лет назад | |
CVE-2021-41378 Windows NTFS Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 5 лет назад | |
CVE-2021-41377 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | почти 5 лет назад | |
CVE-2021-41376 Azure Sphere Information Disclosure Vulnerability | CVSS3: 2.3 | 1% Низкий | почти 5 лет назад | |
CVE-2021-41375 Azure Sphere Information Disclosure Vulnerability | CVSS3: 4.4 | 1% Низкий | почти 5 лет назад | |
CVE-2021-41374 Azure Sphere Information Disclosure Vulnerability | CVSS3: 6.7 | 1% Низкий | почти 5 лет назад | |
CVE-2021-41373 FSLogix Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-41372 Power BI Report Server Spoofing Vulnerability | CVSS3: 7.6 | 1% Низкий | почти 5 лет назад | |
CVE-2021-41371 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | CVSS3: 4.4 | 1% Низкий | почти 5 лет назад | |
CVE-2021-41370 NTFS Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | почти 5 лет назад | |
CVE-2021-4136 Heap-based Buffer Overflow in vim/vim | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу