CVE-2023-27409
- EPSS 0.07%
- Veröffentlicht 09.05.2023 13:15:16
- Zuletzt bearbeitet 21.11.2024 07:52:51
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on...
CVE-2023-27408
- EPSS 0.03%
- Veröffentlicht 09.05.2023 13:15:16
- Zuletzt bearbeitet 21.11.2024 07:52:51
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The `i2c` mutex file is created with the permissions bits of `-rw-rw-rw-`. This file is used as a mutex for multiple applications interacting with i2c. This could allow an...
CVE-2023-27407
- EPSS 1.22%
- Veröffentlicht 09.05.2023 13:15:16
- Zuletzt bearbeitet 21.11.2024 07:52:51
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote att...
CVE-2022-0847
- EPSS 83.71%
- Veröffentlicht 10.03.2022 17:44:57
- Zuletzt bearbeitet 30.07.2025 19:10:07
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user co...
CVE-2021-4034
- EPSS 86.52%
- Veröffentlicht 28.01.2022 20:15:12
- Zuletzt bearbeitet 03.04.2025 18:53:12
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pk...
CVE-2021-36221
- EPSS 0.18%
- Veröffentlicht 08.08.2021 06:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:20
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
CVE-2021-3449
- EPSS 13.18%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but incl...