CVE-2021-4189
- EPSS 0.41%
- Published 24.08.2022 16:15:09
- Last modified 21.11.2024 06:37:06
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious ...
CVE-2021-3656
- EPSS 0.06%
- Published 04.03.2022 19:15:08
- Last modified 21.11.2024 06:22:05
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the ...
CVE-2021-23214
- EPSS 0.59%
- Published 04.03.2022 16:15:08
- Last modified 21.11.2024 05:51:23
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certif...
CVE-2021-3677
- EPSS 0.26%
- Published 02.03.2022 23:15:08
- Last modified 21.11.2024 06:22:08
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objec...
CVE-2022-0711
- EPSS 66.48%
- Published 02.03.2022 22:15:08
- Last modified 21.11.2024 06:39:14
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service cond...
CVE-2021-41819
- EPSS 0.88%
- Published 01.01.2022 06:15:07
- Last modified 22.05.2025 15:15:54
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
CVE-2021-41817
- EPSS 0.54%
- Published 01.01.2022 05:15:08
- Last modified 21.11.2024 06:26:48
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
CVE-2021-4104
- EPSS 72.2%
- Published 14.12.2021 12:15:12
- Last modified 21.11.2024 06:36:54
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppen...
CVE-2021-32672
- EPSS 0.29%
- Published 04.10.2021 18:15:08
- Last modified 21.11.2024 06:07:30
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions o...
- EPSS 94.43%
- Published 16.09.2021 15:15:07
- Last modified 16.05.2025 15:27:13
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.