VYPR

Enterprise Linux Server

by Red Hat

CVEs (3,563)

  • CVE-2021-3575HigMar 4, 2022
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.

  • CVE-2021-26252HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

  • CVE-2021-3551HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager.…

  • CVE-2021-45417HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.00

    AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

  • CVE-2021-45078HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix…

  • CVE-2021-39251HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

  • CVE-2021-33285HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which…

  • CVE-2021-3612HigJul 9, 2021
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The…

  • CVE-2021-3498HigApr 19, 2021
    risk 0.51cvss 7.8epss 0.02

    GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.

  • CVE-2021-3497HigApr 19, 2021
    risk 0.51cvss 7.8epss 0.01

    GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.

  • CVE-2021-3404HigMar 4, 2021
    risk 0.51cvss 7.8epss 0.02

    In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

  • CVE-2021-3403HigMar 4, 2021
    risk 0.51cvss 7.8epss 0.02

    In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.

  • CVE-2021-20194HigFeb 23, 2021
    risk 0.51cvss 7.8epss 0.00

    There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of…

  • CVE-2020-25712HigDec 15, 2020
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2020-14351HigDec 3, 2020
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data…

  • CVE-2020-3864HigOct 27, 2020
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.

  • CVE-2020-14382HigSep 16, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file…

  • CVE-2020-14362HigSep 15, 2020
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…

  • CVE-2020-14361HigSep 15, 2020
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…

  • CVE-2020-14346HigSep 15, 2020
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as…

Page 42 of 179