Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 222

Количество 56 222

redhat логотип

CVE-2021-4192

больше 4 лет назад

vim is vulnerable to Use After Free

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2021-4190

больше 4 лет назад

Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-4189

больше 4 лет назад

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2021-4187

больше 4 лет назад

vim is vulnerable to Use After Free

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2021-4186

больше 4 лет назад

Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-41865

почти 5 лет назад

HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2021-41864

почти 5 лет назад

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2021-4185

больше 4 лет назад

Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-4184

больше 4 лет назад

Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-4183

больше 4 лет назад

Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-4182

больше 4 лет назад

Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-4181

больше 4 лет назад

Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-41819

почти 5 лет назад

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-41817

почти 5 лет назад

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-41816

почти 5 лет назад

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-4180

больше 4 лет назад

An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would give sensitive information which may aid in additional system exploitation. This flaw affects openstack-tripleo-heat-templates versions prior to 11.6.1.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2021-41803

почти 4 года назад

HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2021-41802

почти 5 лет назад

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2021-41800

почти 5 лет назад

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2021-41799

почти 5 лет назад

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-4192

vim is vulnerable to Use After Free

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-4190

Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-4189

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-4187

vim is vulnerable to Use After Free

CVSS3: 7.3
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-4186

Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-41865

HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.

CVSS3: 4.9
1%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-41864

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

CVSS3: 7.8
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-4185

Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-4184

Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-4183

Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-4182

Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-4181

Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-41819

CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-41817

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-41816

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.

CVSS3: 7.5
5%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-4180

An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would give sensitive information which may aid in additional system exploitation. This flaw affects openstack-tripleo-heat-templates versions prior to 11.6.1.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-41803

HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."

CVSS3: 7.1
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-41802

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.

CVSS3: 5.4
1%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-41800

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.

CVSS3: 5.3
2%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-41799

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.

CVSS3: 6.5
2%
Низкий
почти 5 лет назад

Уязвимостей на страницу