Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 222

Количество 56 222

redhat логотип

CVE-2021-39922

почти 5 лет назад

Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-39921

почти 5 лет назад

NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-39920

почти 5 лет назад

NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-3984

почти 5 лет назад

vim is vulnerable to Heap-based Buffer Overflow

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2021-3982

почти 5 лет назад

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to possible DoS of other services running in the same machine.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-3981

почти 5 лет назад

A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2021-3979

больше 4 лет назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-3975

почти 5 лет назад

A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2021-3974

почти 5 лет назад

vim is vulnerable to Use After Free

CVSS3: 2.9
EPSS: Низкий
redhat логотип

CVE-2021-3973

почти 5 лет назад

vim is vulnerable to Heap-based Buffer Overflow

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2021-39715

больше 4 лет назад

In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-178379135References: Upstream kernel

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2021-39714

больше 4 лет назад

In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-205573273References: Upstream kernel

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2021-39713

больше 4 лет назад

Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2021-39711

больше 4 лет назад

In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154175781References: Upstream kernel

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2021-39698

больше 4 лет назад

In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-185125206References: Upstream kernel

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2021-3968

почти 5 лет назад

vim is vulnerable to Heap-based Buffer Overflow

CVSS3: 2.9
EPSS: Низкий
redhat логотип

CVE-2021-39686

больше 4 лет назад

In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-200688826References: Upstream kernel

CVSS3: 8.4
EPSS: Низкий
redhat логотип

CVE-2021-39685

больше 4 лет назад

In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210292376References: Upstream kernel

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2021-39648

больше 5 лет назад

In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-160822094References: Upstream kernel

CVSS3: 4.1
EPSS: Низкий
redhat логотип

CVE-2021-39636

почти 5 лет назад

In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-39922

Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
5%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-39921

NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-39920

NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-3984

vim is vulnerable to Heap-based Buffer Overflow

CVSS3: 7.3
1%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-3982

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and eventually load code to increase its process scheduler priority leading to possible DoS of other services running in the same machine.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-3981

A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.

CVSS3: 3.3
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-3979

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-3975

A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 5.3
2%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-3974

vim is vulnerable to Use After Free

CVSS3: 2.9
1%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-3973

vim is vulnerable to Heap-based Buffer Overflow

CVSS3: 7.8
2%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-39715

In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-178379135References: Upstream kernel

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-39714

In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-205573273References: Upstream kernel

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-39713

Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel

CVSS3: 7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-39711

In bpf_prog_test_run_skb of test_run.c, there is a possible out of bounds read due to Incorrect Size Value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-154175781References: Upstream kernel

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-39698

In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-185125206References: Upstream kernel

CVSS3: 7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-3968

vim is vulnerable to Heap-based Buffer Overflow

CVSS3: 2.9
2%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-39686

In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-200688826References: Upstream kernel

CVSS3: 8.4
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-39685

In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210292376References: Upstream kernel

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-39648

In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-160822094References: Upstream kernel

CVSS3: 4.1
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-39636

In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel

CVSS3: 4.4
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу