CVE-2022-27774
- EPSS 0.51%
- Published 02.06.2022 14:15:43
- Last modified 21.11.2024 06:56:09
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to ...
CVE-2022-22576
- EPSS 0.27%
- Published 26.05.2022 17:15:09
- Last modified 21.11.2024 06:47:03
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for th...
CVE-2021-3772
- EPSS 0.16%
- Published 02.03.2022 23:15:09
- Last modified 21.11.2024 06:22:23
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP ad...
CVE-2020-29569
- EPSS 0.07%
- Published 15.12.2020 17:15:14
- Last modified 21.11.2024 05:24:13
An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when stopped. However, the handler may not have time to ru...
CVE-2020-29374
- EPSS 0.02%
- Published 28.11.2020 07:15:11
- Last modified 21.11.2024 05:23:56
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and there...
CVE-2020-25645
- EPSS 0.1%
- Published 13.10.2020 20:15:12
- Last modified 21.11.2024 05:18:19
A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two e...
CVE-2020-12464
- EPSS 0.08%
- Published 29.04.2020 18:15:13
- Last modified 21.11.2024 04:59:45
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
CVE-2018-20836
- EPSS 1.88%
- Published 07.05.2019 14:29:00
- Last modified 21.11.2024 04:02:16
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.