CVE-2022-0330
- EPSS 0.05%
- Published 25.03.2022 19:15:10
- Last modified 21.11.2024 06:38:23
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
CVE-2021-3656
- EPSS 0.06%
- Published 04.03.2022 19:15:08
- Last modified 21.11.2024 06:22:05
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the ...
- EPSS 28.45%
- Published 21.02.2022 15:15:07
- Last modified 23.04.2025 19:15:51
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fru...
CVE-2021-4091
- EPSS 0.18%
- Published 18.02.2022 18:15:10
- Last modified 21.11.2024 06:36:53
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
- EPSS 0.28%
- Published 18.02.2022 18:15:08
- Last modified 21.11.2024 05:18:34
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and a...
CVE-2020-25717
- EPSS 0.2%
- Published 18.02.2022 18:15:08
- Last modified 21.11.2024 05:18:33
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
CVE-2016-2124
- EPSS 0.79%
- Published 18.02.2022 18:15:08
- Last modified 21.11.2024 02:47:52
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
CVE-2021-4034
- EPSS 86.52%
- Published 28.01.2022 20:15:12
- Last modified 03.04.2025 18:53:12
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pk...
- EPSS 94.43%
- Published 16.09.2021 15:15:07
- Last modified 16.05.2025 15:27:13
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2019-13755
- EPSS 1.85%
- Published 10.12.2019 22:15:15
- Last modified 21.11.2024 04:25:39
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page.