CVE-2021-38198
- EPSS 0.08%
- Veröffentlicht 08.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:37
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.
CVE-2021-38199
- EPSS 0.34%
- Veröffentlicht 08.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:38
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during tru...
CVE-2021-38204
- EPSS 0.07%
- Veröffentlicht 08.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:39
drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.
CVE-2021-38205
- EPSS 0.07%
- Veröffentlicht 08.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:39
drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).
CVE-2021-36221
- EPSS 0.23%
- Veröffentlicht 08.08.2021 06:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:20
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
CVE-2021-38173
- EPSS 0.2%
- Veröffentlicht 07.08.2021 19:15:06
- Zuletzt bearbeitet 21.11.2024 06:16:33
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.
CVE-2021-38166
- EPSS 0.1%
- Veröffentlicht 07.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:32
In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.
CVE-2021-38165
- EPSS 4.28%
- Veröffentlicht 07.08.2021 18:15:06
- Zuletzt bearbeitet 21.11.2024 06:16:32
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
CVE-2021-38160
- EPSS 0.07%
- Veröffentlicht 07.08.2021 04:15:06
- Zuletzt bearbeitet 05.05.2025 14:12:40
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is...
CVE-2021-3655
- EPSS 0.02%
- Veröffentlicht 05.08.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:22:05
A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.