CVE-2021-37600
- EPSS 0.05%
- Veröffentlicht 30.07.2021 14:15:18
- Zuletzt bearbeitet 21.11.2024 06:15:30
An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Librar...
CVE-2021-35942
- EPSS 1.2%
- Veröffentlicht 22.07.2021 18:15:23
- Zuletzt bearbeitet 01.05.2025 18:10:02
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of in...
CVE-2021-3541
- EPSS 0.07%
- Veröffentlicht 09.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:48
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
CVE-2021-3530
- EPSS 0.06%
- Veröffentlicht 02.06.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:21:46
A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
CVE-2021-3520
- EPSS 0.13%
- Veröffentlicht 02.06.2021 13:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:44
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. Th...
CVE-2021-3516
- EPSS 0.36%
- Veröffentlicht 01.06.2021 14:15:10
- Zuletzt bearbeitet 21.11.2024 06:21:43
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availabi...
CVE-2021-23017
- EPSS 76.12%
- Veröffentlicht 01.06.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:09
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
CVE-2020-14301
- EPSS 0.26%
- Veröffentlicht 27.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:02:57
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive inform...
CVE-2021-25217
- EPSS 0.41%
- Veröffentlicht 26.05.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:54:34
In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspecti...
CVE-2021-3559
- EPSS 0.37%
- Veröffentlicht 24.05.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:50
A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client wit...