|
411
|
6.5
4.0
|
MEDIUM
Network
|
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
|
CWE-287
Improper Authentication
|
CVE-2022-0996
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:39
2022-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
412
|
7.5
6.9
|
HIGH
Local
|
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the…
|
CWE-416
Use After Free
|
CVE-2021-3748
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
413
|
7.8
4.6
|
HIGH
Local
|
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap …
|
CWE-787
Out-of-bounds Write
|
CVE-2022-27666
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:56
2022-03-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
414
|
7.8
4.6
|
HIGH
Local
|
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, r…
|
CWE-416
Use After Free
|
CVE-2022-1011
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 15:39
2022-03-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
415
|
7.5
5.0
|
HIGH
Network
|
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggere…
|
NVD-CWE-noinfo
|
CVE-2022-0918
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:39
2022-03-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
416
|
6.5
2.1
|
MEDIUM
Local
|
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wi…
|
-
|
CVE-2021-20257
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 14:46
2022-03-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
417
|
7.8
7.2
|
HIGH
Local
|
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus …
|
CWE-665
Improper Initialization
|
CVE-2022-0847
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:39
2022-03-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
418
|
7.8
4.6
|
HIGH
Local
|
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obt…
|
NVD-CWE-noinfo
|
CVE-2022-0516
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:38
2022-03-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
419
|
7.5
5.0
|
HIGH
Network
|
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates t…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-3698
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
420
|
4.3
4.3
|
MEDIUM
Network
|
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be use…
|
-
|
CVE-2021-3660
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|