VYPR

linux

by Debian

Source repositories

CVEs (10,018)

  • CVE-2021-28660HigMar 17, 2021
    risk 0.00cvss 8.8epss 0.01

    rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work);…

  • CVE-2020-36281HigMar 12, 2021
    risk 0.00cvss 7.5epss 0.03

    Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.

  • CVE-2020-36279HigMar 12, 2021
    risk 0.00cvss 7.5epss 0.03

    Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.

  • CVE-2020-36278HigMar 12, 2021
    risk 0.00cvss 7.5epss 0.03

    Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.

  • CVE-2020-36277HigMar 11, 2021
    risk 0.00cvss 7.5epss 0.02

    Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.

  • CVE-2021-21381HigMar 11, 2021
    risk 0.00cvss 7.1epss 0.02

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to gain access to files that would…

  • CVE-2021-21375MedMar 10, 2021
    risk 0.00cvss 6.5epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP version 2.10 and earlier, after an initial INVITE has been sent, when two 183 responses are received,…

  • CVE-2020-35524HigMar 9, 2021
    risk 0.00cvss 7.8epss 0.02

    A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system…

  • CVE-2020-35523HigMar 9, 2021
    risk 0.00cvss 7.8epss 0.02

    An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as…

  • CVE-2021-27363MedMar 7, 2021
    risk 0.00cvss 4.4epss 0.01

    An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via…

  • CVE-2021-28038MedMar 5, 2021
    risk 0.00cvss 6.5epss 0.01

    An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of…

  • CVE-2021-26932MedFeb 17, 2021
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failure of each one is reported to the backend driver, and the…

  • CVE-2021-26931MedFeb 17, 2021
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory…

  • CVE-2021-26930HigFeb 17, 2021
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encountered. In one case, an error encountered earlier might be…

  • CVE-2021-27229HigFeb 16, 2021
    risk 0.00cvss 8.8epss 0.03

    Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.

  • CVE-2021-26676MedFeb 9, 2021
    risk 0.00cvss 6.5epss 0.01

    gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.

  • CVE-2021-26675HigFeb 9, 2021
    risk 0.00cvss 8.8epss 0.01

    A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.

  • CVE-2021-26910HigFeb 8, 2021
    risk 0.00cvss 7.8epss 0.00

    Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.

  • CVE-2021-3348HigFeb 1, 2021
    risk 0.00cvss 7.0epss 0.00

    nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3d71.

  • CVE-2021-3347HigJan 29, 2021
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.

Page 432 of 501