CVE-2022-2601
- EPSS 0.07%
- Published 14.12.2022 21:15:10
- Last modified 21.11.2024 07:01:19
A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow...
CVE-2014-0144
- EPSS 0.41%
- Published 29.09.2022 03:15:11
- Last modified 21.11.2024 02:01:28
QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execut...
CVE-2014-0147
- EPSS 0.08%
- Published 29.09.2022 03:15:11
- Last modified 21.11.2024 02:01:28
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrect...
CVE-2014-0148
- EPSS 0.08%
- Published 29.09.2022 03:15:11
- Last modified 21.11.2024 02:01:28
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive othe...
CVE-2021-3669
- EPSS 0.01%
- Published 26.08.2022 16:15:09
- Last modified 21.11.2024 06:22:06
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
CVE-2021-3975
- EPSS 0.26%
- Published 23.08.2022 20:15:08
- Last modified 21.11.2024 06:23:17
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAl...
CVE-2021-23177
- EPSS 0.05%
- Published 23.08.2022 16:15:09
- Last modified 21.11.2024 05:51:19
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extrac...
CVE-2021-31566
- EPSS 0.04%
- Published 23.08.2022 16:15:09
- Last modified 21.11.2024 06:05:55
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger...
CVE-2021-3659
- EPSS 0.02%
- Published 22.08.2022 15:15:13
- Last modified 21.11.2024 06:22:05
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerabili...
CVE-2021-3695
- EPSS 0.06%
- Published 06.07.2022 16:15:08
- Last modified 21.11.2024 06:22:10
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue ha...