CVE-2021-20257
- EPSS 0.04%
- Veröffentlicht 16.03.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:13
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to cons...
CVE-2022-0847
- EPSS 83.71%
- Veröffentlicht 10.03.2022 17:44:57
- Zuletzt bearbeitet 30.07.2025 19:10:07
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user co...
CVE-2022-0516
- EPSS 0.11%
- Veröffentlicht 10.03.2022 17:44:56
- Zuletzt bearbeitet 21.11.2024 06:38:49
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw aff...
CVE-2021-3733
- EPSS 0.68%
- Veröffentlicht 10.03.2022 17:42:59
- Zuletzt bearbeitet 21.11.2024 06:22:16
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication r...
CVE-2021-3698
- EPSS 0.15%
- Veröffentlicht 10.03.2022 17:42:57
- Zuletzt bearbeitet 21.11.2024 06:22:10
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Cert...
CVE-2021-3660
- EPSS 0.27%
- Veröffentlicht 10.03.2022 17:42:55
- Zuletzt bearbeitet 21.11.2024 06:22:05
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar...
CVE-2021-3656
- EPSS 0.06%
- Veröffentlicht 04.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:05
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the ...
CVE-2021-3737
- EPSS 0.21%
- Veröffentlicht 04.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:17
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from...
CVE-2021-3575
- EPSS 0.42%
- Veröffentlicht 04.03.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:53
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
CVE-2021-23214
- EPSS 0.59%
- Veröffentlicht 04.03.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:23
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certif...