CVEs (237)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectLinux+2 more12Debian Linux Enterprise LinuxFedora+9 moreNov 21, 2024 Dec 22, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object. |
2Ksmbd Project Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreNov 21, 2024 Dec 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag whe...Show more |
3Netapp NodejsOpenssl16500f Firmware A250 FirmwareCloud Backup+13 moreNov 21, 2024 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of me...Show more |
2Linux Netapp10Cloud Backup H300e FirmwareH300s Firmware+7 moreNov 21, 2024 Dec 8, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an...Show more |
5Debian FedoraprojectLinux+2 more15Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+12 moreNov 21, 2024 Nov 17, 2021 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). |
4Debian FedoraprojectLinux+1 more11Cloud Backup Debian LinuxFedora+8 moreNov 21, 2024 Nov 17, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a...Show more |
3Debian GmplibNetapp8Active Iq Unified Manager Debian LinuxGmp+5 moreNov 21, 2024 Nov 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms. |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreNov 21, 2024 Oct 28, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in the Linux kernel before 5.14.8. A use-after-free in selinux_ptrace_traceme (aka the SELinux handler for PTRACE_TRACEME) could be used by local attackers to cause memory corruption and escalate...Show more |
6Debian FedoraprojectIsc+3 more15Bind Cloud BackupDebian Linux+12 moreNov 21, 2024 Oct 27, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development b...Show more |
6Drupal FedoraprojectJqueryui+3 more27Agile Plm Application ExpressBanking Platform+24 moreNov 4, 2025 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in...Show more |
7Debian DrupalFedoraproject+4 more28Agile Plm Application ExpressBanking Platform+25 moreNov 21, 2024 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fi...Show more |
7Debian DrupalFedoraproject+4 more29Agile Plm Application ExpressBanking Platform+26 moreNov 21, 2024 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixe...Show more |
3Fedoraproject LinuxNetapp10Fedora H300e FirmwareH300s Firmware+7 moreNov 21, 2024 Oct 21, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display dri...Show more |
2Linux Netapp10H300e Firmware H300s FirmwareH410c Firmware+7 moreNov 21, 2024 Oct 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the ker...Show more |
3Debian LinuxNetapp11Debian Linux H300e FirmwareH300s Firmware+8 moreNov 21, 2024 Oct 5, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access. |
4Debian FedoraprojectLinux+1 more15Cloud Backup Debian LinuxFedora+12 moreNov 21, 2024 Oct 2, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write. |
3Debian LinuxNetapp11Cloud Backup Debian LinuxH300e Firmware+8 moreNov 21, 2024 Sep 20, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs be...Show more |
4Debian FedoraprojectLinux+1 more13Cloud Backup Debian LinuxFedora+10 moreNov 21, 2024 Sep 19, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/ma...Show more |
4Debian FedoraprojectLinux+1 more16Aff A250 Firmware Debian LinuxFas 500f Firmware+13 moreNov 21, 2024 Sep 3, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13. |
4Netapp OracleRedhat+1 more19Active Iq Unified Manager Cloud BackupClustered Data Ontap+16 moreNov 21, 2024 Jul 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. |