CVE-2021-3537
- EPSS 0.16%
- Veröffentlicht 14.05.2021 20:15:16
- Zuletzt bearbeitet 21.11.2024 06:21:47
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could...
- EPSS 0.02%
- Veröffentlicht 13.05.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:09
An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it i...
CVE-2020-27824
- EPSS 0.27%
- Veröffentlicht 13.05.2021 14:15:17
- Zuletzt bearbeitet 21.11.2024 05:21:52
A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to s...
CVE-2021-3504
- EPSS 0.15%
- Veröffentlicht 11.05.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:21:42
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memor...
CVE-2021-31916
- EPSS 0.03%
- Veröffentlicht 06.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:30
An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gai...
CVE-2021-3507
- EPSS 0.03%
- Veröffentlicht 06.05.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:42
A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileg...
CVE-2021-3501
- EPSS 0.04%
- Veröffentlicht 06.05.2021 13:15:12
- Zuletzt bearbeitet 21.11.2024 06:21:41
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat f...
CVE-2021-20254
- EPSS 1.76%
- Veröffentlicht 05.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:13
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negativ...
CVE-2021-3472
- EPSS 0.09%
- Veröffentlicht 26.04.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:37
A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as s...
CVE-2021-20208
- EPSS 0.37%
- Veröffentlicht 19.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:07
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity...