CVEs (14,557)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Netapp10Cloud Backup H300e FirmwareH300s Firmware+7 moreJun 17, 2026 May 21, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order t...Show more |
TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling. |
3Debian LinuxNetapp11Cloud Backup Debian LinuxH300e Firmware+8 moreJun 17, 2026 May 17, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat fro...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 May 14, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value. |
The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writin...Show more |
2Linux Netapp12Cloud Backup H300e FirmwareH300s Firmware+9 moreJun 17, 2026 May 14, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs a...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 May 13, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whether it is NULL or not, and may lead to a NULL-ptr deref crash. |
4Debian FedoraprojectLinux+1 more10Cloud Backup Debian LinuxFedora+7 moreJul 30, 2026 May 12, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 May 11, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST sup...Show more |
4Arista DebianLinux+1 more8C 65 Firmware C 75 FirmwareDebian Linux+5 moreJun 17, 2026 May 11, 2021 N/A· v4 5.4 MEDIUM· v3 3.2 LOW· v2 An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and...Show more |
8Arista CiscoDebian+5 more1811100 4p Firmware 1100 8p Firmware1100 Firmware+178 moreJun 17, 2026 May 11, 2021 N/A· v4 3.5 LOW· v3 2.9 LOW· v2 The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices...Show more |
6Arista CiscoDebian+3 more1681100 4p Firmware 1100 8p Firmware1100 Firmware+165 moreJun 17, 2026 May 11, 2021 N/A· v4 2.6 LOW· v3 1.8 LOW· v2 The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse th...Show more |
5Arista DebianIeee+2 more24Ac 1550 Firmware Ac 3165 FirmwareAc 3168 Firmware+21 moreJun 17, 2026 May 11, 2021 N/A· v4 3.5 LOW· v3 2.9 LOW· v2 The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under t...Show more |
3Debian LinuxNetapp11Cloud Backup Debian LinuxH300e Firmware+8 moreJun 17, 2026 May 10, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller. |
An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 May 6, 2021 N/A· v4 6.7 MEDIUM· v3 6.1 MEDIUM· v2 An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (C...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 May 6, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecti...Show more |
2Linux Netapp11Cloud Backup H300e FirmwareH300s Firmware+8 moreJun 17, 2026 May 6, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access t...Show more |
4Fedoraproject LinuxNetapp+1 more19Cloud Backup Enterprise LinuxEnterprise Linux For Real Time+16 moreJun 17, 2026 May 6, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-boun...Show more |
5Broadcom DebianFedoraproject+2 more15Brocade Fabric Operating System Cloud BackupDebian Linux+12 moreJul 30, 2026 Apr 22, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called w...Show more |