Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Garrett Tucker

#21563of 53,632
11.1Total CVSS
Vulnerabilities · 2
Low
1
High
1
PT-2023-6477
7.8
2023-03-10
Oracle · Jre · CVE-2023-26464
**Name of the Vulnerable Software and Affected Versions** Apache Log4j versions prior to 2 **Description** The issue is related to the Chainsaw and SocketAppender components in Log4j 1.x when used with JRE less than 1.7. An attacker can cause a logging entry involving a specially-crafted hashmap or hashtable to be processed, potentially exhausting the available memory in the virtual machine and achieving Denial of Service when the object is deserialized. **Recommendations** Update to Log4j 2.x to resolve the issue. As a temporary workaround, consider restricting the use of the Chainsaw and SocketAppender components until a patch is available. Avoid using deeply nested hashmaps or hashtables in logging entries to minimize the risk of exploitation.
PT-2021-21108
3.3
2021-07-01
Selinux · Selinux · CVE-2021-36087
Name of the Vulnerable Software and Affected Versions: SELinux version 3.2 Description: The issue is related to a heap-based buffer over-read in the `ebitmap match any` function, which is called indirectly from `cil check neverallow`. This occurs due to a lack of checks for invalid statements in an optional block. Recommendations: For SELinux version 3.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.