Show filters
515 Total Results
Displaying 21-30 of 515
Sort by:
Attacker Value
Unknown
CVE-2021-20225
Disclosure Date: March 03, 2021 (last updated November 08, 2023)
A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
0
Attacker Value
Unknown
CVE-2020-27779
Disclosure Date: March 03, 2021 (last updated November 08, 2023)
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
0
Attacker Value
Unknown
CVE-2020-25632
Disclosure Date: March 03, 2021 (last updated November 08, 2023)
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
0
Attacker Value
Unknown
CVE-2014-8141
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
0
Attacker Value
Unknown
CVE-2014-8140
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
0
Attacker Value
Unknown
CVE-2014-8139
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
0
Attacker Value
Unknown
CVE-2015-3147
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.
0
Attacker Value
Unknown
CVE-2014-7844
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
0
Attacker Value
Unknown
CVE-2018-12207
Disclosure Date: November 14, 2019 (last updated November 08, 2023)
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
0
Attacker Value
Unknown
CVE-2019-11135
Disclosure Date: November 14, 2019 (last updated November 08, 2023)
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
0