Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 356

Количество 25 356

msrc логотип

CVE-2021-4034

больше 4 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Критический
msrc логотип

CVE-2021-40330

почти 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-4032

больше 4 лет назад

A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memory errors that happens during VCPU construction which allows an attacker with special user privilege to cause a denial of service. This flaw affects kernel versions prior to 5.15 rc7.

CVSS3: 4.4
EPSS: Низкий
msrc логотип

CVE-2021-4023

больше 4 лет назад

A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allows a local user with permissions to execute io-uring requests to possibly crash the system.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-4019

больше 4 лет назад

Heap-based Buffer Overflow in vim/vim

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-40153

больше 4 лет назад

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2021-40145

больше 4 лет назад

gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete and should only be used for development and testing purposes.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-4002

больше 4 лет назад

A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.

CVSS3: 4.4
EPSS: Низкий
msrc логотип

CVE-2021-4001

больше 4 лет назад

A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a missing lock in kernel/bpf/syscall.c. In this flaw a local user with a special privilege (cap_sys_admin or cap_bpf) can modify the frozen mapped address space. This flaw affects kernel versions prior to 5.16 rc2.

CVSS3: 4.1
EPSS: Низкий
msrc логотип

CVE-2021-3999

почти 4 года назад

A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-3998

почти 4 года назад

A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value potentially leading to information leakage and disclosure of sensitive data.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-3997

почти 4 года назад

A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-3996

10 месяцев назад

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-3995

10 месяцев назад

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-39929

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-39928

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-39926

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-39925

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-39924

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-39923

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
95%
Критический
больше 4 лет назад
msrc логотип
CVSS3: 7.5
3%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-4032

A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memory errors that happens during VCPU construction which allows an attacker with special user privilege to cause a denial of service. This flaw affects kernel versions prior to 5.15 rc7.

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-4023

A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allows a local user with permissions to execute io-uring requests to possibly crash the system.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-4019

Heap-based Buffer Overflow in vim/vim

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 8.1
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-40145

gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete and should only be used for development and testing purposes.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-4002

A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.

CVSS3: 4.4
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-4001

A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a missing lock in kernel/bpf/syscall.c. In this flaw a local user with a special privilege (cap_sys_admin or cap_bpf) can modify the frozen mapped address space. This flaw affects kernel versions prior to 5.16 rc2.

CVSS3: 4.1
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-3999

A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-3998

A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value potentially leading to information leakage and disclosure of sensitive data.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-3997

A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

CVSS3: 5.5
2%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-3996

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

CVSS3: 5.5
1%
Низкий
10 месяцев назад
msrc логотип
CVE-2021-3995

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

CVSS3: 5.5
1%
Низкий
10 месяцев назад
msrc логотип
CVSS3: 7.5
4%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
6%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
8%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
8%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
5%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу