VYPR
Vendor

Grsecurity

Products
4
CVEs
8
Across products
12
Status
Private

Products

4

Recent CVEs

8
  • CVE-2007-0257HigJan 16, 2007
    risk 0.54cvss 7.8epss 0.01

    Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function,…

  • CVE-2023-3811MedJul 21, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file patientprofile.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2019-5023MedOct 31, 2019
    risk 0.38cvss 5.9epss 0.01

    An exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linux-4.9.8-test1 to 4.9.24-test7, grsecurity official from version grsecurity-3.1-4.9.8-201702060653 to grsecurity-3.1-4.9.24-201704252333, grsecurity unofficial…

  • CVE-2010-3373MedOct 29, 2019
    risk 0.36cvss 5.5epss 0.00

    paxtest handles temporary files insecurely

  • CVE-2002-1826Dec 31, 2002
    risk 0.03cvss epss 0.01

    grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory.

  • CVE-2008-1940Apr 25, 2008
    risk 0.00cvss epss 0.00

    The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (2) sys_setfsgid calls, which allows local users to bypass restrictions for those calls.

  • CVE-2007-0253Jan 16, 2007
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital Armaments 20070110 pre-advisory. NOTE: the grsecurity developer has disputed this issue, stating…

  • CVE-2006-0228Jan 17, 2006
    risk 0.00cvss epss 0.00

    The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active.