Vulnerabilities > Debian > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-07 CVE-2021-39260 Out-of-bounds Write vulnerability in multiple products
A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.
local
low complexity
tuxera debian CWE-787
7.8
2021-09-07 CVE-2021-39261 Out-of-bounds Write vulnerability in multiple products
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.
local
low complexity
tuxera debian CWE-787
7.8
2021-09-07 CVE-2021-39262 Out-of-bounds Write vulnerability in multiple products
A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.
local
low complexity
tuxera debian CWE-787
7.8
2021-09-07 CVE-2021-39263 Out-of-bounds Write vulnerability in multiple products
A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G < 2021.8.22.
local
low complexity
tuxera debian CWE-787
7.8
2021-09-07 CVE-2021-33285 Out-of-bounds Write vulnerability in multiple products
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service.
local
low complexity
tuxera redhat fedoraproject debian CWE-787
7.8
2021-09-07 CVE-2021-33289 Out-of-bounds Write vulnerability in multiple products
In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
local
low complexity
tuxera debian fedoraproject CWE-787
7.8
2021-09-07 CVE-2021-35268 Out-of-bounds Write vulnerability in multiple products
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
local
low complexity
tuxera debian fedoraproject CWE-787
7.8
2021-09-07 CVE-2021-35269 Out-of-bounds Write vulnerability in multiple products
NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
local
low complexity
tuxera debian fedoraproject CWE-787
7.8
2021-09-03 CVE-2021-40490 Race Condition vulnerability in multiple products
A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
local
high complexity
linux fedoraproject debian netapp CWE-362
7.0
2021-09-01 CVE-2021-36046 Out-of-bounds Write vulnerability in multiple products
XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user.
local
low complexity
adobe debian CWE-787
7.8