Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 355

Количество 25 355

msrc логотип

CVE-2021-38593

почти 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-38578

11 месяцев назад

Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

EPSS: Низкий
msrc логотип

CVE-2021-38561

почти 2 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-3847

больше 1 года назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-38300

почти 5 лет назад

arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed the 128 KB limit of the MIPS architecture.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-38297

почти 5 лет назад

Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module when GOARCH=wasm GOOS=js is used.

CVSS3: 9.8
EPSS: Средний
msrc логотип

CVE-2021-38209

почти 5 лет назад

net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX NF_SYSCTL_CT_EXPECT_MAX and NF_SYSCTL_CT_BUCKETS sysctls.

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2021-38208

почти 5 лет назад

net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NULL pointer dereference and BUG) by making a getsockname call after a certain type of failure of a bind call.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-38207

почти 5 лет назад

drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-38206

почти 5 лет назад

The mac80211 subsystem in the Linux kernel before 5.12.13 when a device supporting only 5 GHz is used allows attackers to cause a denial of service (NULL pointer dereference in the radiotap parser) by injecting a frame with 802.11a rates.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-38205

почти 5 лет назад

drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e. the real IOMEM pointer).

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2021-38204

почти 5 лет назад

drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2021-38203

почти 5 лет назад

btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-38202

почти 5 лет назад

fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-38201

почти 5 лет назад

net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-38200

почти 5 лет назад

arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13 on systems with perf_event_paranoid=-1 and no specific PMU driver support registered allows local users to cause a denial of service (perf_instruction_pointer NULL pointer dereference and OOPS) via a "perf record" command.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-38199

почти 5 лет назад

fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-38198

почти 5 лет назад

arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page leading to a missing guest protection page fault.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-38191

11 месяцев назад

An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread.

EPSS: Низкий
msrc логотип

CVE-2021-38190

около 2 лет назад

An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it does not ensure that the number of elements is equal to the product of the row count and column count.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 7.5
3%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38578

Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

1%
Низкий
11 месяцев назад
msrc логотип
CVSS3: 7.5
1%
Низкий
почти 2 года назад
msrc логотип
CVSS3: 7.8
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2021-38300

arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can exceed the 128 KB limit of the MIPS architecture.

CVSS3: 7.8
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38297

Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module when GOARCH=wasm GOOS=js is used.

CVSS3: 9.8
10%
Средний
почти 5 лет назад
msrc логотип
CVE-2021-38209

net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX NF_SYSCTL_CT_EXPECT_MAX and NF_SYSCTL_CT_BUCKETS sysctls.

CVSS3: 3.3
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38208

net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NULL pointer dereference and BUG) by making a getsockname call after a certain type of failure of a bind call.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38207

drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38206

The mac80211 subsystem in the Linux kernel before 5.12.13 when a device supporting only 5 GHz is used allows attackers to cause a denial of service (NULL pointer dereference in the radiotap parser) by injecting a frame with 802.11a rates.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38205

drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e. the real IOMEM pointer).

CVSS3: 3.3
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38204

drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.

CVSS3: 6.8
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38203

btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38202

fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd.

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38201

net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38200

arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13 on systems with perf_event_paranoid=-1 and no specific PMU driver support registered allows local users to cause a denial of service (perf_instruction_pointer NULL pointer dereference and OOPS) via a "perf record" command.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38199

fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38198

arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page leading to a missing guest protection page fault.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-38191

An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread.

1%
Низкий
11 месяцев назад
msrc логотип
CVE-2021-38190

An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it does not ensure that the number of elements is equal to the product of the row count and column count.

CVSS3: 9.8
1%
Низкий
около 2 лет назад

Уязвимостей на страницу