Search

Found 5,160 results in 685ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-3796 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:4517: vim security update (Moderate)
CVE-2021-3778 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:4517: vim security update (Moderate)
CVE-2021-23336 medium 5.5 FIX arch arch sles rocky 5y ago The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.pars…
CVE-2019-19005 medium 5.5 rhel 5y ago RHSA-2021:4519: autotrace security update (Moderate)
CVE-2019-19004 medium 5.5 rhel 5y ago RHSA-2021:4519: autotrace security update (Moderate)
CVE-2021-36087 medium 5.5 FIX rockydebian debian rhel 5y ago RHSA-2021:4513: libsepol security update (Moderate)
CVE-2021-36086 medium 5.5 FIX rockydebian debian rhel 5y ago RHSA-2021:4513: libsepol security update (Moderate)
CVE-2021-36085 medium 5.5 FIX rockydebian debian rhel 5y ago RHSA-2021:4513: libsepol security update (Moderate)
CVE-2021-36084 medium 5.5 FIX rockydebian debian rhel 5y ago RHSA-2021:4513: libsepol security update (Moderate)
CVE-2021-22925 medium 5.5 FIX arch archdebian debian sles 5y ago curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parse…
CVE-2021-22898 medium 5.5 FIX arch archdebian debian sles 5y ago curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers…
CVE-2021-22876 medium 5.5 FIX arch archdebian debian sles 5y ago curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip o…
CVE-2021-3445 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4464: dnf security and bug fix update (Moderate)
CVE-2021-3580 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:4451: gnutls and nettle security, bug fix, and enhancement update (Moderate)
CVE-2021-20232 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:4451: gnutls and nettle security, bug fix, and enhancement update (Moderate)
CVE-2021-20231 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:4451: gnutls and nettle security, bug fix, and enhancement update (Moderate)
CVE-2019-17595 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4426: ncurses security update (Moderate)
CVE-2019-17594 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4426: ncurses security update (Moderate)
CVE-2021-3565 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:4413: tpm2-tools security and enhancement update (Moderate)
CVE-2021-33560 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:4409: libgcrypt security and bug fix update (Moderate)
CVE-2021-3426 medium 5.5 FIX arch arch sles rocky 5y ago There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disc…
CVE-2020-13435 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4396: sqlite security update (Moderate)
CVE-2019-5827 medium 5.5 FIX debian debian rocky rhel 5y ago Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-19603 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4396: sqlite security update (Moderate)
CVE-2019-13751 medium 5.5 FIX arch archdebian debian rocky 5y ago Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2019-13750 medium 5.5 FIX arch archdebian debian rocky 5y ago Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
CVE-2020-10001 medium 5.5 FIX arch archdebian debian rocky 5y ago RHSA-2021:4393: cups security and bug fix update (Moderate)
CVE-2021-3800 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:4385: glib2 security and bug fix update (Moderate)
CVE-2021-25214 medium 5.5 FIX debian debianarch arch sles 5y ago RHSA-2021:4384: bind security and bug fix update (Moderate)
CVE-2021-30799 medium 5.5 FIX arch arch rockydebian debian 5y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave…
CVE-2021-30797 medium 5.5 FIX arch arch rockydebian debian 5y ago This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to code …
CVE-2021-30795 medium 5.5 FIX arch arch rockydebian debian 5y ago A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web co…
CVE-2021-30758 medium 5.5 FIX arch arch rockydebian debian 5y ago A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web conte…
CVE-2021-30749 medium 5.5 FIX arch arch sles rocky 5y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing …
CVE-2021-30744 medium 5.5 FIX arch arch rockydebian debian 5y ago Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big S…
CVE-2021-30734 medium 5.5 FIX arch arch rockydebian debian 5y ago Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing …
CVE-2021-30720 medium 5.5 FIX arch arch rockydebian debian 5y ago A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to …
CVE-2021-30689 medium 5.5 FIX arch arch rockydebian debian 5y ago A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted …
CVE-2021-30682 medium 5.5 FIX arch arch rockydebian debian 5y ago A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able…
CVE-2021-28650 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:4381: GNOME security, bug fix, and enhancement update (Moderate)
CVE-2021-21806 medium 5.5 FIX arch arch sles rocky 5y ago An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in remote code execution.…
CVE-2021-21779 medium 5.5 FIX arch arch sles rocky 5y ago A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further…
CVE-2021-21775 medium 5.5 FIX arch arch sles rocky 5y ago A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak…
CVE-2021-1844 medium 5.5 FIX arch arch sles rocky 5y ago A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur…
CVE-2021-1801 medium 5.5 FIX arch arch sles rocky 5y ago This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.…
CVE-2021-1799 medium 5.5 FIX arch arch sles rocky 5y ago A port redirection issue was addressed with additional port validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watch…
CVE-2021-1788 medium 5.5 FIX arch arch sles rocky 5y ago A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS…
CVE-2021-1765 medium 5.5 FIX arch arch sles rocky 5y ago This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Maliciously crafted w…
CVE-2020-36241 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:4381: GNOME security, bug fix, and enhancement update (Moderate)
CVE-2020-29623 medium 5.5 FIX arch arch sles rocky 5y ago "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security…
CVE-2020-27918 medium 5.5 FIX arch arch sles rocky 5y ago A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS …
CVE-2020-24870 medium 5.5 FIX rockydebian debian rhel 5y ago RHSA-2021:4381: GNOME security, bug fix, and enhancement update (Moderate)
CVE-2020-13558 medium 5.5 FIX arch arch sles rocky 5y ago A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can lead to a use after free.
CVE-2019-18218 medium 5.5 FIX arch arch slesdebian debian 5y ago cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
CVE-2020-14145 medium 5.5 sles rockydebian debian 5y ago The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connect…
CVE-2021-3487 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:4364: binutils security update (Moderate)
CVE-2021-20284 medium 5.5 FIX debian debian sles rocky 5y ago RHSA-2021:4364: binutils security update (Moderate)
CVE-2021-20197 medium 5.5 FIX debian debianarch arch sles 5y ago RHSA-2021:4364: binutils security update (Moderate)
CVE-2020-35448 medium 5.5 FIX debian debianarch arch sles 5y ago RHSA-2021:4364: binutils security update (Moderate)
CVE-2020-13529 medium 5.5 FIX arch arch sles rocky 5y ago An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing att…
CVE-2021-35942 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:4358: glibc security, bug fix, and enhancement update (Moderate)
CVE-2021-33574 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:4358: glibc security, bug fix, and enhancement update (Moderate)
CVE-2021-27645 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:4358: glibc security, bug fix, and enhancement update (Moderate)
CVE-2021-3732 medium 5.5 FIX arch arch slesdebian debian 5y ago A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not…
CVE-2021-3679 medium 5.5 FIX arch arch slesdebian debian 5y ago A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (…
CVE-2021-3659 medium 5.5 FIX slesdebian debianalmalinux almalinux 5y ago A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash t…
CVE-2021-3635 medium 5.5 FIX slesdebian debianalmalinux almalinux 5y ago A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
CVE-2021-3600 medium 5.5 FIX slesdebian debianalmalinux almalinux 5y ago It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use th…
CVE-2021-3573 medium 5.5 FIX arch arch slesdebian debian 5y ago A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregist…
CVE-2021-3564 medium 5.5 FIX arch arch slesdebian debian 5y ago A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to c…
CVE-2021-3489 medium 5.5 FIX arch arch slesdebian debian 5y ago The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes withi…
CVE-2021-3348 medium 5.5 FIX arch arch slesdebian debian 5y ago nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O requ…
CVE-2021-33200 medium 5.5 FIX arch arch slesdebian debian 5y ago kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and write…
CVE-2021-33033 medium 5.5 FIX slesdebian debianalmalinux almalinux 5y ago The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd.…
CVE-2021-31916 medium 5.5 FIX slesdebian debianalmalinux almalinux 5y ago An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker…
CVE-2021-31829 medium 5.5 FIX arch arch slesdebian debian 5y ago kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific co…
CVE-2021-31440 medium 5.5 FIX arch arch slesdebian debian 5y ago This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the tar…
CVE-2021-29650 medium 5.5 FIX arch arch slesdebian debian 5y ago An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/…
CVE-2021-29646 medium 5.5 FIX arch archdebian debianalmalinux almalinux 5y ago An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes, aka CID-0217ed2848e8.
CVE-2021-29155 medium 5.5 FIX arch arch slesdebian debian 5y ago An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spe…
CVE-2021-28971 medium 5.5 FIX arch arch slesdebian debian 5y ago In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PE…
CVE-2021-28950 medium 5.5 FIX arch arch slesdebian debian 5y ago An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.
CVE-2021-23133 medium 5.5 FIX arch arch slesdebian debian 5y ago A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_des…
CVE-2021-20239 medium 5.5 FIX slesdebian debianalmalinux almalinux 5y ago A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest …
CVE-2021-20194 medium 5.5 FIX arch arch slesdebian debian 5y ago There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARD…
CVE-2021-0129 medium 5.5 FIX debian debian slesalmalinux almalinux 5y ago Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access.
CVE-2020-36386 medium 5.5 FIX slesdebian debianalmalinux almalinux 5y ago An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf.
CVE-2020-36312 medium 5.5 FIX slesdebian debianalmalinux almalinux 5y ago An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d.
CVE-2020-36158 medium 5.5 FIX arch arch slesdebian debian 5y ago mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID…
CVE-2020-29660 medium 5.5 FIX arch arch slesdebian debian 5y ago A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIO…
CVE-2020-29368 medium 5.5 FIX slesdebian debian rhel 5y ago An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a T…
CVE-2020-27777 medium 5.5 FIX slesdebian debian rhel 5y ago A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors …
CVE-2020-26147 medium 5.5 FIX arch arch slesdebian debian 5y ago An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused …
CVE-2020-26146 medium 5.3 5.3 arch arch sles rhel samsungaristasiemens 5y ago An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfi…
CVE-2020-26145 medium 5.5 FIX arch arch slesdebian debian 5y ago An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and proces…
CVE-2020-26144 medium 5.5 arch arch sles rhel 5y ago RHSA-2021:4356: kernel security, bug fix, and enhancement update (Moderate)
CVE-2020-26143 medium 5.5 arch arch sles rhel 5y ago RHSA-2021:4356: kernel security, bug fix, and enhancement update (Moderate)
CVE-2020-26141 medium 5.5 FIX arch arch slesdebian debian 5y ago An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adver…
CVE-2020-26140 medium 5.5 arch arch sles rhel 5y ago RHSA-2021:4356: kernel security, bug fix, and enhancement update (Moderate)
CVE-2020-26139 medium 5.5 FIX arch arch slesdebian debian 5y ago An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be…