Vulnerabilities

Summary — last 7 days

New vulnerabilities2,786▼ 305 vs. last week
Critical / high1,290▼ 231 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (4.4)0.40%—Iproute2 Project Iproute2Canonical Ubuntu Linux5/9/20206/17/2026
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may…
ModifiedLow (3.3)0.35%—Iproute2 Project Iproute22/15/20146/16/2026
iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.
ModifiedMedium (4.9)0.40%—Stephen Hemminger Iproute12/15/20036/16/2026
iproute 2.4.7 and earlier allows local users to cause a denial of service via spoofed messages as other users to the kernel netlink interface.
ModifiedMedium (5)1.2%—David F. Mischler Iproute12/31/20016/16/2026
IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header.
Orbitaley — Vulnerabilities