CVE-2021-28694
- EPSS 0.14%
- Veröffentlicht 27.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:09
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left u...
CVE-2021-28695
- EPSS 0.14%
- Veröffentlicht 27.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:09
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left u...
CVE-2021-28696
- EPSS 0.09%
- Veröffentlicht 27.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:09
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left u...
CVE-2021-28697
- EPSS 0.06%
- Veröffentlicht 27.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:09
grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 statu...
CVE-2021-28698
- EPSS 0.06%
- Veröffentlicht 27.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:10
long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may create to map grants offered by other domains. In the process of carrying out certain actions, Xen woul...
CVE-2021-28699
- EPSS 0.07%
- Veröffentlicht 27.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:10
inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant status. That is, when operating in this mode, a guest has two tables. As a result, guests also need to be able to retrieve the add...
CVE-2021-28700
- EPSS 2.13%
- Veröffentlicht 27.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:10
xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond wh...
CVE-2021-40153
- EPSS 0.54%
- Veröffentlicht 27.08.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:23:40
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination dire...
CVE-2021-30591
- EPSS 0.59%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:14
Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30592
- EPSS 0.25%
- Veröffentlicht 26.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:15
Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.