Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Michael Brown

#15117of 53,633
17.8Total CVSS
Vulnerabilities · 2
High
2
PT-2021-3379
7.8
2021-05-19
Linux · Xen-Netback · CVE-2021-28691
**Name of the Vulnerable Software and Affected Versions** Linux xen-netback (affected versions not specified) **Description** A use-after-free issue exists in Linux xen-netback due to insufficient input validation. This can be triggered by a malicious or buggy network PV frontend sending a malformed packet, causing the interface to be disabled and the receive kernel thread associated with queue 0 to terminate. As a result, when the backend is destroyed, a use-after-free occurs because the kernel thread associated with queue 0 has already exited, leading to a call to `kthread stop` being performed against a stale pointer. The exploitation of this issue may allow a remote attacker to elevate privileges or disclose protected information. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2003-2302
10
2003-12-31
Proxyview · Proxyview · CVE-2003-1357
**Name of the Vulnerable Software and Affected Versions** ProxyView (affected versions not specified) **Description** The issue allows remote attackers to gain access due to a default administrator password of 'Administrator' for Embedded Windows NT. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.