CVE-2021-2121
published 2021-01-20CVE-2021-2121: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily…
PriorityP418medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.43%
35.1th percentile
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virtualbox | < virtualbox 6.1.18-dfsg-1 (sid) | virtualbox 6.1.18-dfsg-1 (sid) |
| offis | dcmtk | >= 0 < 3.6.4-2.1ubuntu0.1 | 3.6.4-2.1ubuntu0.1 |
| offis | dcmtk | >= 0 < 3.6.1~20150924-5ubuntu0.1~esm2 | 3.6.1~20150924-5ubuntu0.1~esm2 |
| offis | dcmtk | >= 0 < 3.6.2-3ubuntu0.1~esm2 | 3.6.2-3ubuntu0.1~esm2 |
| offis | dcmtk | >= 0 < 3.6.6-5ubuntu0.1~esm2 | 3.6.6-5ubuntu0.1~esm2 |
| offis | dcmtk | >= 0 < 3.6.7-9.1ubuntu0.1~esm1 | 3.6.7-9.1ubuntu0.1~esm1 |
| oracle | vm_virtualbox | < 6.1.18 | 6.1.18 |
| oracle_corporation | vm_virtualbox | >= unspecified < 6.1.18 | 6.1.18 |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian6.0MEDIUM
vendor_oracle6.0MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue
vendor_redhat·2025-09-16·CVSS 5.5
CVE-2023-53280 [MEDIUM] CWE-824 kernel: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue
kernel: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue
System crash when qla2x00_start_sp(sp) returns error code EGAIN and wake_up
gets called for uninitialized wait queue sp->nvme_ls_waitq.
qla2xxx [0000:37:00.1]-2121:5: Returning existing qpair of ffff8ae2c0513400 for idx=0
qla2xxx [0000:37:00.1]-700e:5: qla2x00_start_sp failed = 11
BUG: unable to handle kernel NULL pointer dereference at 0000000000000000
PGD 0 P4D 0
Oops: 0000 [#1] SMP NOPTI
Hardware name: HPE ProLiant DL360 Gen10/ProLiant DL360 Gen10, BIOS U32 09/03/2021
Workqueue: nvme-wq nvme_fc_connect_ctrl_work [nvme_fc]
RIP: 0010:__wake_up_common+0x4c/0x190
RSP: 0018:ffff95f3e0cb7cd0 EFLAGS: 00010086
RA
Oracle
Oracle Oracle Virtualization Risk Matrix: Core — CVE-2021-2121
vendor_oracle·2021-01-15·CVSS 6.0
CVE-2021-2121 [MEDIUM] Oracle Oracle Virtualization Risk Matrix: Core — CVE-2021-2121
Oracle Oracle Virtualization Risk Matrix: Core vulnerability
CVE: CVE-2021-2121
CVSS: 6.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2021 (JAN 2021)
Debian
CVE-2021-2121: virtualbox - Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (comp...
vendor_debian·2021·CVSS 6.0
CVE-2021-2121 [MEDIUM] CVE-2021-2121: virtualbox - Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (comp...
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
Scope: local
sid: resolved (fixed in 6.1.18-dfsg-1)
OSV
dcmtk vulnerabilities
osv·2024-09-17·CVSS 7.5
CVE-2021-41687 dcmtk vulnerabilities
dcmtk vulnerabilities
Jinsheng Ba discovered that DCMTK incorrectly handled certain requests. If
a user or an automated system were tricked into opening a certain specially
crafted input file, a remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 20.04 LTS.
(CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, CVE-2021-41690)
Sharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled
pointers. If a user or an automated system were tricked into opening a
certain specially crafted input file, a remote attacker could possibly use
this issue to cause a denial of service. This issue only affected
Ubuntu 20.04 LTS. (CVE-2022-2121)
It was discovered that DCMTK incorrectly handled certain inputs. If a
user or an automated system w
GHSA
GHSA-8g3p-9292-vwfx: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)
ghsa_unreviewed·2022-05-24
CVE-2021-2121 [MEDIUM] GHSA-8g3p-9292-vwfx: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
OSV
CVE-2021-2121: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)
osv·2021-01-20·CVSS 6.0
CVE-2021-2121 [MEDIUM] CVE-2021-2121: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
No detection rules found.
No public exploits indexed.
2021-01-20
Published