vciy

Parallels Desktop: 20 records in one advisory

20 records announced together, published between 2020-08-25 and 2022-07-15, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://kb.parallels.com/en/125013. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

8 of 20 records name something of its own. For the other 12, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-190: Integer Overflow or Wraparound.

What this page does not cover

This batch is 20 of the 40 records that cite the same advisory. The other 20 are different findings announced alongside it.

None of those 20 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2020-17390hypervisor kernel extensionCWE-125: Out-of-bounds Read
CVE-2020-17392host_ioctl_set_kernel_symbolsCWE-822: Untrusted Pointer Dereference
CVE-2020-17395prl_naptd processCWE-191: Integer Underflow (Wrap or Wraparound)
CVE-2020-17396moduleCWE-190: Integer Overflow or Wraparound
CVE-2020-17397handling network packetsCWE-119: Improper Restriction of Operations…
CVE-2020-17399no title heldCWE-129: Improper Validation of Array Index
CVE-2020-17400no title heldCWE-129: Improper Validation of Array Index
CVE-2021-27242no title heldCWE-787: Out-of-bounds Write
CVE-2021-27243no title heldCWE-190: Integer Overflow or Wraparound
CVE-2021-27259no title heldCWE-190: Integer Overflow or Wraparound
CVE-2021-27278no title heldCWE-22: Improper Limitation of a Pathname to a…
CVE-2021-31420no title heldCWE-121: Stack-based Buffer Overflow
CVE-2021-31422e1000eCWE-367: Time-of-check Time-of-use (TOCTOU)…
CVE-2021-31424no title heldCWE-122: Heap-based Buffer Overflow
CVE-2021-31425no title heldCWE-190: Integer Overflow or Wraparound
CVE-2021-31426no title heldCWE-190: Integer Overflow or Wraparound
CVE-2021-31428no title heldCWE-122: Heap-based Buffer Overflow
CVE-2021-31429no title heldCWE-122: Heap-based Buffer Overflow
CVE-2021-34986abuseCWE-367: Time-of-check Time-of-use (TOCTOU)…
CVE-2021-34987hdaudioCWE-120: Buffer Copy without Checking Size of…

20 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.