Vulnerabilities

Summary — last 7 days

New vulnerabilities2,744▼ 71 vs. last week
Critical / high1,416▲ 184 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)106▼ 394 vs. last week
–

9 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.8)0.33%—Sysstat Project SysstatFedoraproject FedoraDebian Linux5/18/20236/17/2026
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
ModifiedHigh (7.8)1.2%—Sysstat Project SysstatDebian LinuxFedoraproject Fedora11/8/20226/17/2026
sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocate_structures function insufficiently checks bounds before arithmetic multiplication, allowing for…
ModifiedCritical (9.8)2.6%—Sysstat Project SysstatDebian LinuxCanonical Ubuntu Linux12/11/20196/17/2026
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
ModifiedMedium (5.5)1.5%—Sysstat Project SysstatFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+19/9/20196/17/2026
sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
ModifiedMedium (5.5)0.82%—Sysstat Project Sysstat11/24/20186/17/2026
An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memset call, as demonstrated by sadf.
ModifiedHigh (7.8)1.7%—Sysstat Project Sysstat11/21/20186/17/2026
An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memmove call, as demonstrated by sadf.
ModifiedMedium (4.4)0.42%—Sysstat8/14/20076/16/2026
The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code.
ModifiedMedium (4.6)0.36%—Redhat SysstatSGI PropackSysstat4/15/20046/16/2026
The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.
ModifiedMedium (4.6)0.39%—Redhat SysstatSGI PropackSysstat4/15/20046/16/2026
The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.