Логотип exploitDog
bind:"CVE-2021-35937" OR bind:"CVE-2021-35939" OR bind:"CVE-2021-35938"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-35937" OR bind:"CVE-2021-35939" OR bind:"CVE-2021-35938"

Количество 24

Количество 24

rocky логотип

RLSA-2024:0647

больше 1 года назад

Moderate: rpm security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0647

больше 1 года назад

ELSA-2024-0647: rpm security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0463

больше 1 года назад

ELSA-2024-0463: rpm security update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20240410-21

больше 1 года назад

Множественные уязвимости rpm

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-35937

почти 3 года назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2021-35937

около 4 лет назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2021-35937

почти 3 года назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2021-35937

почти 3 года назад

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2021-35937

почти 3 года назад

A race condition vulnerability was found in rpm. A local unprivileged ...

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-63x9-9q4w-j636

почти 3 года назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
EPSS: Низкий
fstec логотип

BDU:2021-03555

около 4 лет назад

Уязвимость менеджера RPM-пакетов RPM (RPM Package Manager) операционных систем Red Hat Enterprise Linux, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2021-35938

почти 3 года назад

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2021-35938

около 4 лет назад

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-35938

почти 3 года назад

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2021-35938

почти 3 года назад

A symbolic link issue was found in rpm. It occurs when rpm sets the de ...

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2021-35939

почти 3 года назад

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2021-35939

около 4 лет назад

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-35939

почти 3 года назад

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2021-35939

почти 3 года назад

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2021-35939

почти 3 года назад

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was inco ...

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:0647

Moderate: rpm security update

больше 1 года назад
oracle-oval логотип
ELSA-2024-0647

ELSA-2024-0647: rpm security update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-0463

ELSA-2024-0463: rpm security update (MODERATE)

больше 1 года назад
redos логотип
ROS-20240410-21

Множественные уязвимости rpm

CVSS3: 6.5
больше 1 года назад
ubuntu логотип
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 6.4
0%
Низкий
почти 3 года назад
debian логотип
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged ...

CVSS3: 6.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-63x9-9q4w-j636

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2021-03555

Уязвимость менеджера RPM-пакетов RPM (RPM Package Manager) операционных систем Red Hat Enterprise Linux, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-35938

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2021-35938

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-35938

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
debian логотип
CVE-2021-35938

A symbolic link issue was found in rpm. It occurs when rpm sets the de ...

CVSS3: 6.7
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 6.7
0%
Низкий
почти 3 года назад
debian логотип
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was inco ...

CVSS3: 6.7
0%
Низкий
почти 3 года назад

Уязвимостей на страницу