VYPR

linux

by Debian

Source repositories

CVEs (10,018)

  • CVE-2021-35039HigJul 7, 2021
    risk 0.00cvss 7.8epss 0.00

    kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument.

  • CVE-2021-36086LowJul 1, 2021
    risk 0.00cvss 3.3epss 0.01

    The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list).

  • CVE-2021-33624MedJun 23, 2021
    risk 0.00cvss 4.7epss 0.01

    In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.

  • CVE-2021-34693MedJun 14, 2021
    risk 0.00cvss 5.5epss 0.00

    net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.

  • CVE-2021-22895MedJun 11, 2021
    risk 0.00cvss 5.9epss 0.01

    Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.

  • CVE-2017-20005CriJun 6, 2021
    risk 0.00cvss 9.8epss 0.03

    NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

  • CVE-2021-3516HigJun 1, 2021
    risk 0.00cvss 7.8epss 0.02

    There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.

  • CVE-2021-3527MedMay 26, 2021
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array…

  • CVE-2021-33038HigMay 26, 2021
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web…

  • CVE-2020-27815HigMay 26, 2021
    risk 0.00cvss 7.8epss 0.01

    A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality,…

  • CVE-2020-25669HigMay 26, 2021
    risk 0.00cvss 7.8epss 0.01

    A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkbd_disconnect, there is still an alias in sunkbd_reinit causing Use After Free.

  • CVE-2020-25668HigMay 26, 2021
    risk 0.00cvss 7.0epss 0.01

    A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.

  • CVE-2021-32399HigMay 10, 2021
    risk 0.00cvss 7.0epss 0.01

    net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.

  • CVE-2021-31916MedMay 6, 2021
    risk 0.00cvss 6.7epss 0.01

    An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds…

  • CVE-2021-31829MedMay 6, 2021
    risk 0.00cvss 5.5epss 0.00

    kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the…

  • CVE-2021-31873CriApr 30, 2021
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer overflow.

  • CVE-2021-31872CriApr 30, 2021
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overflow or other security impact.

  • CVE-2021-31871HigApr 30, 2021
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems.

  • CVE-2021-31870CriApr 30, 2021
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer overflow.

  • CVE-2021-21417HigApr 29, 2021
    risk 0.00cvss 7.2epss 0.01

    fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file.

Page 430 of 501