|
451
|
5.9
4.3
|
MEDIUM
Network
|
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
|
CWE-287
Improper Authentication
|
CVE-2016-2124
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 11:47
2022-02-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
452
|
9.8
7.5
|
CRITICAL
Network
|
A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
|
NVD-CWE-noinfo
|
CVE-2021-3773
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 15:22
2022-02-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
453
|
4.7
1.9
|
MEDIUM
Local
|
A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_i…
|
-
|
CVE-2021-3753
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 15:22
2022-02-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
454
|
7.1
7.9
|
HIGH
Adjacent
|
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to…
|
CWE-362
Race Condition
|
CVE-2021-3752
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 15:22
2022-02-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
455
|
7.8
4.4
|
HIGH
Local
|
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-3551
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:21
2022-02-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
456
|
5.5
4.3
|
MEDIUM
Local
|
Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF f…
|
CWE-476
NULL Pointer Dereference
|
CVE-2022-0561
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:38
2022-02-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
457
|
5.5
4.3
|
MEDIUM
Local
|
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specia…
|
NVD-CWE-Other
|
CVE-2022-0530
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:38
2022-02-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
458
|
5.5
4.3
|
MEDIUM
Local
|
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specia…
|
CWE-787
Out-of-bounds Write
|
CVE-2022-0529
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:38
2022-02-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
459
|
5.5
2.1
|
MEDIUM
Local
|
A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may imp…
|
CWE-416
Use After Free
|
CVE-2022-0487
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:38
2022-02-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
460
|
8.8
7.2
|
HIGH
Local
|
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation b…
|
CWE-416
Use After Free
|
CVE-2021-4154
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:37
2022-02-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|