VYPR

grsecurity

by Grsecurity

CVEs (5)

  • CVE-2023-3811MedJul 21, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file patientprofile.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2019-5023MedOct 31, 2019
    risk 0.38cvss 5.9epss 0.01

    An exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linux-4.9.8-test1 to 4.9.24-test7, grsecurity official from version grsecurity-3.1-4.9.8-201702060653 to grsecurity-3.1-4.9.24-201704252333, grsecurity unofficial…

  • CVE-2002-1826Dec 31, 2002
    risk 0.03cvss epss 0.01

    grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory.

  • CVE-2008-1940Apr 25, 2008
    risk 0.00cvss epss 0.00

    The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (2) sys_setfsgid calls, which allows local users to bypass restrictions for those calls.

  • CVE-2006-0228Jan 17, 2006
    risk 0.00cvss epss 0.00

    The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active.