CVE-2021-28691
- EPSS 0.04%
- Published 29.06.2021 12:15:08
- Last modified 21.11.2024 06:00:09
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malfor...
CVE-2020-28097
- EPSS 0.16%
- Published 24.06.2021 12:15:07
- Last modified 21.11.2024 05:22:21
The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85.
CVE-2021-22901
- EPSS 0.34%
- Published 11.06.2021 16:15:11
- Last modified 21.11.2024 05:50:52
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentia...
CVE-2021-22897
- EPSS 1.08%
- Published 11.06.2021 16:15:10
- Last modified 21.11.2024 05:50:51
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" ...
CVE-2020-36387
- EPSS 0.06%
- Published 07.06.2021 20:15:08
- Last modified 21.11.2024 05:29:23
An issue was discovered in the Linux kernel before 5.8.2. fs/io_uring.c has a use-after-free related to io_async_task_func and ctx reference holding, aka CID-6d816e088c35.
CVE-2018-25015
- EPSS 0.07%
- Published 07.06.2021 20:15:07
- Last modified 21.11.2024 04:03:21
An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8.
CVE-2019-25045
- EPSS 0.15%
- Published 07.06.2021 20:15:07
- Last modified 21.11.2024 04:39:49
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
CVE-2020-36385
- EPSS 0.06%
- Published 07.06.2021 12:15:08
- Last modified 21.11.2024 05:29:22
An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.
CVE-2021-33200
- EPSS 0.03%
- Published 27.05.2021 13:15:08
- Last modified 21.11.2024 06:08:30
kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege esca...
CVE-2020-27815
- EPSS 0.18%
- Published 26.05.2021 13:15:07
- Last modified 21.11.2024 05:21:51
A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerabil...