Vulnerabilities > Serenityos

DATE CVE VULNERABILITY TITLE RISK
2023-03-01 CVE-2021-4327 Integer Overflow or Wraparound vulnerability in Serenityos 20191230
A vulnerability was found in SerenityOS.
network
low complexity
serenityos CWE-190
critical
9.8
2021-06-18 CVE-2021-31272 Path Traversal vulnerability in Serenityos 20191230/20210127/20210327
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.
network
low complexity
serenityos CWE-22
critical
9.8
2021-06-18 CVE-2021-33185 Classic Buffer Overflow vulnerability in Serenityos
SerenityOS contains a buffer overflow in the set_range test in TestBitmap which could allow attackers to obtain sensitive information.
network
low complexity
serenityos CWE-120
7.5
2021-06-18 CVE-2021-33186 Out-of-bounds Write vulnerability in Serenityos
SerenityOS in test-crypto.cpp contains a stack buffer overflow which could allow attackers to obtain sensitive information.
network
low complexity
serenityos CWE-787
7.5
2021-04-06 CVE-2021-30045 Classic Buffer Overflow vulnerability in Serenityos 20210327
SerenityOS 2021-03-27 contains a buffer overflow vulnerability in the EndOfCentralDirectory::read() function.
network
low complexity
serenityos CWE-120
critical
9.1
2021-04-06 CVE-2021-28874 Classic Buffer Overflow vulnerability in Serenityos 20191230/20210127
SerenityOS fixed as of c9f25bca048443e317f1994ba9b106f2386688c3 contains a buffer overflow vulnerability in LibTextCode through opening a crafted file.
local
low complexity
serenityos CWE-120
7.8
2021-04-06 CVE-2021-27343 Classic Buffer Overflow vulnerability in Serenityos
SerenityOS Unspecified is affected by: Buffer Overflow.
network
low complexity
serenityos CWE-120
7.5
2019-12-31 CVE-2019-20172 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Serenityos
Kernel/VM/MemoryManager.cpp in SerenityOS before 2019-12-30 does not reject syscalls with pointers into the kernel-only virtual address space, which allows local users to gain privileges by overwriting a return address that was found on the kernel stack.
local
low complexity
serenityos CWE-119
7.8