Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 355

Количество 25 355

msrc логотип

CVE-2021-34334

больше 4 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-3421

около 5 лет назад

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-34193

почти 3 года назад

Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-3418

больше 5 лет назад

If certificates that signed grub are installed into db grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2021-3416

больше 5 лет назад

A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.

CVSS3: 6
EPSS: Низкий
msrc логотип

CVE-2021-34141

больше 4 лет назад

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-3411

больше 5 лет назад

A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2021-3409

больше 5 лет назад

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

CVSS3: 5.7
EPSS: Низкий
msrc логотип

CVE-2021-33938

почти 5 лет назад

Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-33930

почти 5 лет назад

Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-3392

больше 5 лет назад

A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.

CVSS3: 3.2
EPSS: Низкий
msrc логотип

CVE-2021-33929

почти 5 лет назад

Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-33928

почти 5 лет назад

Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-33910

около 5 лет назад

basic/unit-name.c in systemd prior to 246.15 247.8 248.5 and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-33909

около 5 лет назад

fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations leading to an integer overflow an Out-of-bounds Write and escalation to root by an unprivileged user aka CID-8cae8cd89f05.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-33880

11 месяцев назад

The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.

EPSS: Низкий
msrc логотип

CVE-2021-33788

около 5 лет назад

Windows LSA Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-33786

около 5 лет назад

Windows LSA Security Feature Bypass Vulnerability

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2021-33785

около 5 лет назад

Windows AF_UNIX Socket Provider Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-33784

около 5 лет назад

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 5.5
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-3421

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-34193

Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
msrc логотип
CVE-2021-3418

If certificates that signed grub are installed into db grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

CVSS3: 6.4
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-3416

A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.

CVSS3: 6
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 5.3
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-3411

A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-3409

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

CVSS3: 5.7
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-33938

Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-33930

Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-3392

A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host resulting in a denial of service. Versions between 2.10.0 and 5.2.0 are potentially affected.

CVSS3: 3.2
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-33929

Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-33928

Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-33910

basic/unit-name.c in systemd prior to 246.15 247.8 248.5 and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

CVSS3: 5.5
9%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-33909

fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations leading to an integer overflow an Out-of-bounds Write and escalation to root by an unprivileged user aka CID-8cae8cd89f05.

CVSS3: 7.8
10%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-33880

The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.

2%
Низкий
11 месяцев назад
msrc логотип
CVE-2021-33788

Windows LSA Denial of Service Vulnerability

CVSS3: 7.5
3%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-33786

Windows LSA Security Feature Bypass Vulnerability

CVSS3: 8.1
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-33785

Windows AF_UNIX Socket Provider Denial of Service Vulnerability

CVSS3: 7.5
3%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-33784

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
около 5 лет назад

Уязвимостей на страницу