Known Vulnerabilities for products from Toaruos Project
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Toaruos Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-13049 json | An integer wrap in kernel/sys/syscall.c in ToaruOS 1.10.10 allows users to map arbitrary kernel pages into userland process s... | 7.8 - HIGH | 2019-06-29 | 2022-09-29 |
| CVE-2019-13048 json | kernel/sys/syscall.c in ToaruOS through 1.10.9 allows a denial of service upon a critical error in certain sys_sbrk allocatio... | 5.5 - MEDIUM | 2019-06-29 | 2022-09-29 |
| CVE-2019-13047 json | kernel/sys/syscall.c in ToaruOS through 1.10.9 has incorrect access control in sys_sysfunc case 9 for TOARU_SYS_FUNC_SETHEAP,... | 7.8 - HIGH | 2019-06-29 | 2022-09-29 |
| CVE-2019-13046 json | linker/linker.c in ToaruOS through 1.10.9 has insecure LD_LIBRARY_PATH handling in setuid applications. | 7.8 - HIGH | 2019-06-29 | 2022-09-29 |
| CVE-2019-12937 json | apps/gsudo.c in gsudo in ToaruOS through 1.10.9 has a buffer overflow allowing local privilege escalation to the root user vi... | 7.8 - HIGH | 2019-06-23 | 2022-09-29 |