Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 222

Количество 56 222

redhat логотип

CVE-2021-33928

больше 5 лет назад

Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-33910

около 5 лет назад

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-33909

около 5 лет назад

fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2021-33844

больше 5 лет назад

A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2021-33813

около 5 лет назад

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2021-3377

больше 5 лет назад

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-33670

больше 4 лет назад

SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-33656

больше 5 лет назад

When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2021-33655

около 4 лет назад

When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2021-33646

около 4 лет назад

The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-33645

около 4 лет назад

The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-33644

около 4 лет назад

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2021-33643

около 4 лет назад

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2021-33642

больше 4 лет назад

When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2021-33641

больше 4 лет назад

When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2021-33640

больше 3 лет назад

After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2021-33631

больше 2 лет назад

Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2021-33630

больше 2 лет назад

NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-33624

около 5 лет назад

In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2021-33623

больше 5 лет назад

The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-33928

Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-33910

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

CVSS3: 5.5
9%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-33909

fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.

CVSS3: 7.8
10%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-33844

A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash.

CVSS3: 3.3
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-33813

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

CVSS3: 7.5
19%
Средний
около 5 лет назад
redhat логотип
CVE-2021-3377

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

CVSS3: 6.5
8%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-33670

SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-33656

When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.

CVSS3: 6.8
1%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-33655

When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

CVSS3: 6.7
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-33646

The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-33645

The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-33644

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.

CVSS3: 6.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-33643

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.

CVSS3: 7.4
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-33642

When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function.

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-33641

When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-33640

After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).

CVSS3: 6.2
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-33631

Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2021-33630

NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2021-33624

In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.

CVSS3: 4.7
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-33623

The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.

CVSS3: 7.5
3%
Низкий
больше 5 лет назад

Уязвимостей на страницу