CVE-2021-28039
- EPSS 0.42%
- Veröffentlicht 05.03.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:59:01
An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest...
CVE-2020-14372
- EPSS 1.74%
- Veröffentlicht 03.03.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:03:07
A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) cont...
CVE-2021-20226
- EPSS 0.44%
- Veröffentlicht 23.02.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:10
A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of validating the existence of an object prior to perf...
CVE-2020-8625
- EPSS 64.16%
- Veröffentlicht 17.02.2021 23:15:13
- Zuletzt bearbeitet 21.11.2024 05:39:09
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by...
CVE-2021-26932
- EPSS 0.35%
- Veröffentlicht 17.02.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:04
An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failure of each one is reported to ...
CVE-2021-27218
- EPSS 4.08%
- Veröffentlicht 15.02.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:37
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.
CVE-2021-27219
- EPSS 2.99%
- Veröffentlicht 15.02.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:37
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corrupti...
CVE-2021-23336
- EPSS 35.96%
- Veröffentlicht 15.02.2021 13:15:12
- Zuletzt bearbeitet 17.12.2025 22:15:55
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector c...
- EPSS 1.6%
- Veröffentlicht 05.02.2021 14:15:18
- Zuletzt bearbeitet 21.11.2024 05:56:42
A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the com...
CVE-2021-3156
- EPSS 99.3%
- Veröffentlicht 26.01.2021 21:15:12
- Zuletzt bearbeitet 10.11.2025 14:41:45
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.