CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Starwindsoftware Remove filter Clear all
CVE-2022-32268 HIGH

StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostn…

CVSS 8.8 EPSS 2.31% Jun 3, 2022
CVE-2007-20001 HIGH

A flaw was found in StarWind iSCSI target. An attacker could script standard iSCSI Initiator operation(s) to exhaust the StarWind service socket, which could l…

CVSS 7.5 EPSS 1.06% Feb 6, 2022
CVE-2013-20004 CRITICAL

A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker coul…

CVSS 9.8 EPSS 1.21% Feb 6, 2022
CVE-2022-24551 HIGH

A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any lo…

CVSS 8.8 EPSS 0.89% Feb 6, 2022
CVE-2022-24552 CRITICAL

A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to…

CVSS 9.8 EPSS 1.31% Feb 6, 2022
CVE-2021-4034 KEV HIGH

polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector

CVSS 7.8 EPSS 94.34% Jan 28, 2022
CVE-2022-23858 HIGH

A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects…

CVSS 8.8 EPSS 1.12% Jan 24, 2022
CVE-2021-45389 CRITICAL

A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escala…

CVSS 9.8 EPSS 1.17% Jan 4, 2022
CVE-2021-43527 CRITICAL

nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)

CVSS 9.8 EPSS 17.56% Dec 8, 2021
CVE-2021-42574 HIGH

environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks

CVSS 8.5 EPSS 12.88% Nov 1, 2021
CVE-2021-42739 MEDIUM

kernel: Heap buffer overflow in firedtv driver

CVSS 6.7 EPSS 0.47% Oct 20, 2021
CVE-2021-41617 HIGH

openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured

CVSS 7.0 EPSS 2.54% Sep 26, 2021
CVE-2021-37750 MEDIUM

krb5: NULL pointer dereference in process_tgs_req() in kdc/do_tgs_req.c via a FAST inner body that lacks server field

CVSS 6.5 EPSS 2.17% Aug 23, 2021
CVE-2020-36385 HIGH

kernel: use-after-free in drivers/infiniband/core/ucma.c ctx use-after-free

CVSS 7.8 EPSS 1.48% Jun 7, 2021
CVE-2020-36322 MEDIUM

kernel: fuse: fuse_do_getattr() calls make_bad_inode() in inappropriate situations

CVSS 5.5 EPSS 0.38% Apr 14, 2021
CVE-2021-20271 HIGH

rpm: Signature checks bypass via corrupted rpm package

CVSS 7.0 EPSS 0.79% Mar 26, 2021
CVE-2020-14409 HIGH

SDL2: Integer overflow in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file

CVSS 7.8 EPSS 1.31% Jan 19, 2021
CVE-2020-25704 MEDIUM

kernel: perf_event_parse_addr_filter memory

CVSS 6.2 EPSS 0.35% Dec 2, 2020
CVE-2020-25656 MEDIUM

kernel: use-after-free in read in vt_do_kdgkb_ioctl

CVSS 4.1 EPSS 0.44% Dec 2, 2020
CVE-2020-25643 HIGH

kernel: improper input validation in ppp_cp_parse_cr function leads to memory corruption and read overflow

CVSS 7.2 EPSS 3.29% Oct 6, 2020
CVE-2020-0427 MEDIUM

kernel: out-of-bounds reads in pinctrl subsystem.

CVSS 5.5 EPSS 0.49% Sep 17, 2020
CVE-2020-14314 MEDIUM

kernel: buffer uses out of index in ext3/4 filesystem

CVSS 5.5 EPSS 0.37% Sep 15, 2020
CVE-2020-24394 HIGH

kernel: umask not applied on filesystem without ACL support

CVSS 7.1 EPSS 0.36% Aug 19, 2020
CVE-2019-20807 MEDIUM

vim: users can execute arbitrary OS commands via scripting interfaces in the rvim restricted mode

CVSS 5.3 EPSS 0.49% May 28, 2020
CVE-2018-18585 MEDIUM

libmspack: chmd_read_headers() fails to reject filenames containing NULL bytes

CVSS 4.3 EPSS 3.08% Oct 23, 2018

Showing 1 to 25 CVEs · page 1 (more available)