CVE-2021-45485High· 7.5▾ MidnightPoC availableIn the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically ch…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.6%
1 GitHub repo
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.
linux_kernel < 4.4.276linux_kernel >= 4.5, < 4.9.276linux_kernel >= 4.10, < 4.14.240linux_kernel >= 4.15, < 4.19.198linux_kernel >= 4.20, < 5.4.133linux_kernel >= 5.5, < 5.10.51linux_kernel >= 5.11, < 5.12.18linux_kernel >= 5.13, < 5.13.3e-series_santricity_os_controllersolidfire,_enterprise_sds_&_hci_storage_nodesolidfire_&_hci_management_nodebrocade_fabric_operating_system_firmwarecommunications_cloud_native_core_binding_support_function = 22.1.3communications_cloud_native_core_network_exposure_function = 22.1.1communications_cloud_native_core_policy = 22.2.0all_flash_fabric-attached_storage_8300_firmwarefabric-attached_storage_8300_firmwareall_flash_fabric-attached_storage_8700_firmwarefabric-attached_storage_8700_firmwareaff_a400_firmwarefabric-attached_storage_a400_firmwarehci_compute_node_firmwareh300e_firmwareh300s_firmwareh410c_firmwareh410s_firmwareh500e_firmwareh500s_firmwareh610c_firmwareh610s_firmwareh615c_firmwareh700e_firmwareh700s_firmwareUpgrade past the affected range:
linux_kernel 5.13.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-36180High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36179High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36184High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
CVE-2020-36181High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
CVE-2021-20322High· 7.4A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports
CVE-2021-2351High· 8.3Vulnerability in the Advanced Networking Option component of Oracle Database Server