Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
Unknown

CVE-2021-45261

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.
Attacker Value
Unknown

CVE-2021-3939

Disclosure Date: November 16, 2021 (last updated February 23, 2025)
Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions 0.6.55-0ubuntu12~20.04.5, 0.6.55-0ubuntu13.3, 0.6.55-0ubuntu14.1.
Attacker Value
Unknown

CVE-2021-42377

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.
Attacker Value
Unknown

CVE-2020-12963

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system.
Attacker Value
Unknown

CVE-2020-12982

Disclosure Date: November 09, 2021 (last updated February 22, 2025)
An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
Attacker Value
Unknown

CVE-2021-41073

Disclosure Date: September 19, 2021 (last updated February 23, 2025)
loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.
Attacker Value
Unknown

CVE-2021-28216

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
Attacker Value
Unknown

CVE-2021-3682

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
Attacker Value
Unknown

CVE-2020-36404

Disclosure Date: July 01, 2021 (last updated February 22, 2025)
Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl.
Attacker Value
Unknown

CVE-2021-22760

Disclosure Date: June 11, 2021 (last updated February 22, 2025)
A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.