CVE-2021-3698
- EPSS 0.11%
- Veröffentlicht 10.03.2022 17:42:57
- Zuletzt bearbeitet 21.11.2024 06:22:10
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Cert...
CVE-2021-3660
- EPSS 0.27%
- Veröffentlicht 10.03.2022 17:42:55
- Zuletzt bearbeitet 21.11.2024 06:22:05
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar...
CVE-2021-3656
- EPSS 0.07%
- Veröffentlicht 04.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:05
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the ...
CVE-2021-3737
- EPSS 0.16%
- Veröffentlicht 04.03.2022 19:15:08
- Zuletzt bearbeitet 17.12.2025 22:15:56
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from...
CVE-2021-3575
- EPSS 0.33%
- Veröffentlicht 04.03.2022 18:15:08
- Zuletzt bearbeitet 03.11.2025 20:15:50
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
CVE-2021-23214
- EPSS 0.39%
- Veröffentlicht 04.03.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:23
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certif...
CVE-2021-3602
- EPSS 0.04%
- Veröffentlicht 03.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:57
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When ru...
CVE-2021-3620
- EPSS 0.2%
- Veröffentlicht 03.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:00
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
CVE-2022-0492
- EPSS 6.52%
- Veröffentlicht 03.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:46
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the...
CVE-2021-3716
- EPSS 0.07%
- Veröffentlicht 02.03.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:14
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the ...