CVE-2024-26462
- EPSS 0.02%
- Published 29.02.2024 01:44:18
- Last modified 25.03.2025 20:15:21
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
CVE-2024-26461
- EPSS 0.08%
- Published 29.02.2024 01:44:18
- Last modified 23.05.2025 15:30:30
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
CVE-2024-26458
- EPSS 0.21%
- Published 29.02.2024 01:44:18
- Last modified 23.05.2025 15:39:31
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.
CVE-2022-36879
- EPSS 0.04%
- Published 27.07.2022 04:15:10
- Last modified 05.05.2025 16:15:17
An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.
- EPSS 25.23%
- Published 21.06.2022 15:15:09
- Last modified 15.09.2025 14:15:33
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022...
CVE-2022-0995
- EPSS 22.29%
- Published 25.03.2022 19:15:10
- Last modified 21.11.2024 06:39:49
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of ser...
- EPSS 0.06%
- Published 03.03.2022 19:15:08
- Last modified 21.11.2024 06:21:58
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kerne...
CVE-2021-3772
- EPSS 0.16%
- Published 02.03.2022 23:15:09
- Last modified 21.11.2024 06:22:23
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP ad...
CVE-2020-36516
- EPSS 0.04%
- Published 26.02.2022 04:15:06
- Last modified 21.11.2024 05:29:43
An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.
CVE-2021-45485
- EPSS 0.52%
- Published 25.12.2021 02:15:06
- Last modified 21.11.2024 06:32:18
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among ma...