Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 045

Количество 25 045

msrc логотип

CVE-2021-2036

больше 5 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2021-2032

больше 5 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2021-20322

больше 4 лет назад

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity because software that relies on UDP source port randomization are indirectly affected as well.

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2021-20321

больше 4 лет назад

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2021-20320

больше 4 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-2031

больше 5 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2021-20316

почти 2 года назад

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2021-20305

больше 5 лет назад

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2021-20295

больше 4 лет назад

It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to include the fix for the qemu-kvm component issue CVE-2020-10756 which was previously corrected in virt:rhel/qemu-kvm via erratum RHSA-2020:4059 (https://access.redhat.com/errata/RHSA-2020:4059). CVE-2021-20295 was assigned to that Red Hat specific security regression. For more details about the original security issue CVE-2020-10756 refer to bug 1835986 or the CVE page: https://access.redhat.com/security/cve/CVE-2020-10756.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-20294

около 5 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-20286

почти 2 года назад

CVSS3: 2.7
EPSS: Низкий
msrc логотип

CVE-2021-20277

почти 2 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-20271

больше 5 лет назад

A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package whose signature header was modified to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity confidentiality and system availability.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2021-20270

больше 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-20268

больше 5 лет назад

An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls dev_map_init_map or sock_map_alloc. This flaw allows a local user to crash the system or possibly escalate their privileges. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-20266

около 5 лет назад

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2021-20257

больше 3 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-20255

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-20254

почти 2 года назад

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2021-20251

почти 2 года назад

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2021-2036

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-2032

Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 4.3
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-20322

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity because software that relies on UDP source port randomization are indirectly affected as well.

CVSS3: 7.4
7%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 4.7
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-2031

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
2%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 6.8
1%
Низкий
почти 2 года назад
msrc логотип
CVSS3: 8.1
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-20295

It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to include the fix for the qemu-kvm component issue CVE-2020-10756 which was previously corrected in virt:rhel/qemu-kvm via erratum RHSA-2020:4059 (https://access.redhat.com/errata/RHSA-2020:4059). CVE-2021-20295 was assigned to that Red Hat specific security regression. For more details about the original security issue CVE-2020-10756 refer to bug 1835986 or the CVE page: https://access.redhat.com/security/cve/CVE-2020-10756.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.8
3%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 2.7
1%
Низкий
почти 2 года назад
msrc логотип
CVSS3: 7.5
4%
Низкий
почти 2 года назад
msrc логотип
CVE-2021-20271

A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package whose signature header was modified to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity confidentiality and system availability.

CVSS3: 7
1%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 7.5
3%
Низкий
больше 5 лет назад
msrc логотип
CVE-2021-20268

An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls dev_map_init_map or sock_map_alloc. This flaw allows a local user to crash the system or possibly escalate their privileges. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 4.9
2%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 6.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 6.8
2%
Низкий
почти 2 года назад
msrc логотип
CVSS3: 5.9
1%
Низкий
почти 2 года назад

Уязвимостей на страницу