CVE-2021-3501
- EPSS 0.04%
- Veröffentlicht 06.05.2021 13:15:12
- Zuletzt bearbeitet 21.11.2024 06:21:41
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat f...
CVE-2021-20254
- EPSS 0.65%
- Veröffentlicht 05.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:13
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negativ...
CVE-2021-3472
- EPSS 0.09%
- Veröffentlicht 26.04.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:37
A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as s...
CVE-2021-20208
- EPSS 0.37%
- Veröffentlicht 19.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:07
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity...
CVE-2021-3497
- EPSS 0.23%
- Veröffentlicht 19.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:41
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
CVE-2021-3498
- EPSS 0.24%
- Veröffentlicht 19.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:41
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
CVE-2021-3505
- EPSS 0.13%
- Veröffentlicht 19.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:42
A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called...
CVE-2021-3448
- EPSS 0.04%
- Veröffentlicht 08.04.2021 23:15:12
- Zuletzt bearbeitet 03.12.2025 01:15:46
A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmas...
CVE-2021-3482
- EPSS 0.2%
- Veröffentlicht 08.04.2021 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:21:38
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing mali...
CVE-2021-20305
- EPSS 0.18%
- Veröffentlicht 05.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:19
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possi...