Количество 28
Количество 28
ELSA-2023-5264
ELSA-2023-5264: virt:ol and virt-devel:rhel security and bug fix update (IMPORTANT)

CVE-2022-40284
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.

CVE-2022-40284
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.

CVE-2022-40284
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.

CVE-2022-40284
CVE-2022-40284
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted ...

CVE-2023-3354
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.

CVE-2023-3354
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.

CVE-2023-3354
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.

CVE-2023-3354
CVE-2023-3354
A flaw was found in the QEMU built-in VNC server. When a client connec ...

SUSE-SU-2022:3866-1
Security update for ntfs-3g_ntfsprogs

SUSE-SU-2022:3865-1
Security update for ntfs-3g_ntfsprogs
ELSA-2023-6167
ELSA-2023-6167: libguestfs-winsupport security update (LOW)

BDU:2022-06607
Уязвимость утилиты ntfs-3g набора драйверов NTFS-3G реализации файловой системы NTFS, позволяющая нарушителю выполнить произвольный код

ROS-20230825-05
Уязвимость qemu
GHSA-vhf9-5f69-9hjm
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.
ELSA-2023-5094
ELSA-2023-5094: qemu-kvm security and bug fix update (IMPORTANT)

BDU:2023-05003
Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

ROS-20221103-05
Уязвимость утилиты ntfs-3g
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
ELSA-2023-5264 ELSA-2023-5264: virt:ol and virt-devel:rhel security and bug fix update (IMPORTANT) | почти 2 года назад | |||
![]() | CVE-2022-40284 A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2022-40284 A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device. | CVSS3: 3.3 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2022-40284 A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад |
![]() | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
CVE-2022-40284 A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted ... | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2023-3354 A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад |
![]() | CVE-2023-3354 A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад |
![]() | CVE-2023-3354 A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад |
![]() | CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | |
CVE-2023-3354 A flaw was found in the QEMU built-in VNC server. When a client connec ... | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
![]() | SUSE-SU-2022:3866-1 Security update for ntfs-3g_ntfsprogs | 0% Низкий | больше 2 лет назад | |
![]() | SUSE-SU-2022:3865-1 Security update for ntfs-3g_ntfsprogs | 0% Низкий | больше 2 лет назад | |
ELSA-2023-6167 ELSA-2023-6167: libguestfs-winsupport security update (LOW) | больше 1 года назад | |||
![]() | BDU:2022-06607 Уязвимость утилиты ntfs-3g набора драйверов NTFS-3G реализации файловой системы NTFS, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад |
![]() | ROS-20230825-05 Уязвимость qemu | CVSS3: 7.5 | 0% Низкий | почти 2 года назад |
GHSA-vhf9-5f69-9hjm A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
ELSA-2023-5094 ELSA-2023-5094: qemu-kvm security and bug fix update (IMPORTANT) | почти 2 года назад | |||
![]() | BDU:2023-05003 Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | почти 2 года назад |
![]() | ROS-20221103-05 Уязвимость утилиты ntfs-3g | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу