Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Igor Chervatyuk

Researcher fromIntel IPAS STORM
#17419of 53,633
15.4Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2022-10651
9.8
2022-06-13
Apache · Apache Hadoop · CVE-2021-37404
**Name of the Vulnerable Software and Affected Versions** Apache Hadoop versions prior to 2.10.2 Apache Hadoop versions prior to 3.2.3 Apache Hadoop versions prior to 3.3.2 **Description** There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. This issue occurs when a file path provided by a user is opened without validation, which may result in a denial of service or arbitrary code execution. **Recommendations** For versions prior to 2.10.2, upgrade to Apache Hadoop 2.10.2 or higher. For versions prior to 3.2.3, upgrade to Apache Hadoop 3.2.3 or higher. For versions prior to 3.3.2, upgrade to Apache Hadoop 3.3.2 or higher.
PT-2022-2953
5.6
2022-02-28
Amd · Amd Cpus · CVE-2021-26401
**Name of the Vulnerable Software and Affected Versions** AMD CPUs (affected versions not specified) **Description** The issue is related to the LFENCE/JMP module in AMD CPUs, specifically concerning the branch prediction mechanism. This allows an attacker to access protected memory from a program without the necessary privileges by exploiting indirect branch prediction. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.