Логотип exploitDog
bind:"CVE-2020-27821" OR bind:"CVE-2021-20221" OR bind:"CVE-2020-15469" OR bind:"CVE-2021-3409"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-27821" OR bind:"CVE-2021-20221" OR bind:"CVE-2020-15469" OR bind:"CVE-2021-3409"

Количество 52

Количество 52

msrc логотип

CVE-2021-20221

около 4 лет назад

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2021-20221

около 4 лет назад

An out-of-bounds heap buffer access issue was found in the ARM Generic ...

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3f6w-864h-4prm

около 3 лет назад

An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subsequent processing. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.

CVSS3: 6
EPSS: Низкий
fstec логотип

BDU:2022-05771

больше 4 лет назад

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с записью за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6
EPSS: Низкий
rocky логотип

RLSA-2021:1762

около 4 лет назад

Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-1762

около 4 лет назад

ELSA-2021-1762: virt:ol and virt-devel:rhel security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1244-1

больше 4 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1241-1

больше 4 лет назад

Security update for qemu

EPSS: Низкий
ubuntu логотип

CVE-2021-3409

больше 4 лет назад

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

CVSS3: 5.7
EPSS: Низкий
redhat логотип

CVE-2021-3409

больше 4 лет назад

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2021-3409

больше 4 лет назад

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

CVSS3: 5.7
EPSS: Низкий
msrc логотип

CVE-2021-3409

больше 4 лет назад

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2021-3409

больше 4 лет назад

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffectiv ...

CVSS3: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2020-15469

около 5 лет назад

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

CVSS3: 2.3
EPSS: Низкий
redhat логотип

CVE-2020-15469

около 5 лет назад

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

CVSS3: 2.3
EPSS: Низкий
nvd логотип

CVE-2020-15469

около 5 лет назад

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

CVSS3: 2.3
EPSS: Низкий
msrc логотип

CVE-2020-15469

почти 5 лет назад

CVSS3: 2.3
EPSS: Низкий
debian логотип

CVE-2020-15469

около 5 лет назад

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback m ...

CVSS3: 2.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0363-1

больше 4 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0521-1

больше 4 лет назад

Security update for qemu

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 6
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-20221

An out-of-bounds heap buffer access issue was found in the ARM Generic ...

CVSS3: 6
0%
Низкий
около 4 лет назад
github логотип
GHSA-3f6w-864h-4prm

An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subsequent processing. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.

CVSS3: 6
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-05771

Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с записью за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6
0%
Низкий
больше 4 лет назад
rocky логотип
RLSA-2021:1762

Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update

около 4 лет назад
oracle-oval логотип
ELSA-2021-1762

ELSA-2021-1762: virt:ol and virt-devel:rhel security, bug fix, and enhancement update (MODERATE)

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:1244-1

Security update for qemu

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:1241-1

Security update for qemu

больше 4 лет назад
ubuntu логотип
CVE-2021-3409

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-3409

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-3409

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 5.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-3409

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffectiv ...

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-15469

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

CVSS3: 2.3
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-15469

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

CVSS3: 2.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-15469

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

CVSS3: 2.3
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 2.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-15469

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback m ...

CVSS3: 2.3
0%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0363-1

Security update for qemu

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0521-1

Security update for qemu

больше 4 лет назад

Уязвимостей на страницу