CVE-2020-25670
- EPSS 0.06%
- Veröffentlicht 26.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:18:25
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.
CVE-2020-25671
- EPSS 0.13%
- Veröffentlicht 26.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:18:25
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.
CVE-2020-25673
- EPSS 0.13%
- Veröffentlicht 26.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:18:25
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.
CVE-2021-22543
- EPSS 0.01%
- Veröffentlicht 26.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:50:18
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control...
CVE-2021-31924
- EPSS 0.09%
- Veröffentlicht 26.05.2021 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:31
Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypas...
CVE-2021-33574
- EPSS 0.14%
- Veröffentlicht 25.05.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:09:07
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to...
CVE-2020-25672
- EPSS 2.01%
- Veröffentlicht 25.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:18:25
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
CVE-2020-26555
- EPSS 0.23%
- Veröffentlicht 24.05.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:20:04
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
CVE-2020-26558
- EPSS 0.02%
- Veröffentlicht 24.05.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:20:04
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public ke...
CVE-2021-33477
- EPSS 0.27%
- Veröffentlicht 20.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:08:54
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.