Latest CVE Feed
-
7.1
HIGHCVE-2021-4166
vim is vulnerable to Out-of-bounds Read... Read more
Affected Products : enterprise_linux fedora debian_linux vim macos mac_os_x linux_enterprise factory- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-4162
archivy is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : archivy- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-4161
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.... Read more
Affected Products : mgate_mb3180_firmware mgate_mb3280_firmware mgate_mb3480_firmware mgate_mb3180 mgate_mb3280 mgate_mb3480- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-4160
There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely a... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-4159
A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak in... Read more
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
6.0
MEDIUMCVE-2021-4158
A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.... Read more
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-4157
An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the sy... Read more
Affected Products : linux_kernel fedora h300s_firmware h500s_firmware h700s_firmware h410s_firmware communications_cloud_native_core_binding_support_function h300s h410s h500s +7 more products- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-4156
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could t... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-4155
A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them.... Read more
Affected Products : linux_kernel- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4154
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a... Read more
Affected Products : linux_kernel enterprise_linux virtualization hci_baseboard_management_controller- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-4150
A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call ... Read more
Affected Products : linux_kernel- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-4149
A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-4148
A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-4147
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.... Read more
- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-4146
Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.... Read more
Affected Products : pimcore- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-4145
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest c... Read more
- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-4144
TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.... Read more
- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-4143
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.... Read more
Affected Products : bigbluebutton- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-4142
The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.... Read more
Affected Products : candlepin- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024