Show filters
827 Total Results
Displaying 71-80 of 827
Sort by:
Attacker Value
Unknown
CVE-2022-2153
Disclosure Date: August 31, 2022 (last updated November 29, 2024)
A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.
0
Attacker Value
Unknown
CVE-2022-1355
Disclosure Date: August 31, 2022 (last updated November 29, 2024)
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
0
Attacker Value
Unknown
CVE-2022-0367
Disclosure Date: August 29, 2022 (last updated October 08, 2023)
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
0
Attacker Value
Unknown
CVE-2022-1184
Disclosure Date: August 29, 2022 (last updated December 21, 2023)
A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service.
0
Attacker Value
Unknown
CVE-2022-0171
Disclosure Date: August 26, 2022 (last updated November 29, 2024)
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).
0
Attacker Value
Unknown
CVE-2021-3864
Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.
0
Attacker Value
Unknown
CVE-2021-3669
Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
0
Attacker Value
Unknown
CVE-2022-0135
Disclosure Date: August 25, 2022 (last updated November 29, 2024)
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
0
Attacker Value
Unknown
CVE-2021-4213
Disclosure Date: August 24, 2022 (last updated October 08, 2023)
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
0
Attacker Value
Unknown
CVE-2021-4159
Disclosure Date: August 24, 2022 (last updated October 08, 2023)
A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.
0