CVE-2021-34428
- EPSS 0.51%
- Veröffentlicht 22.06.2021 15:15:16
- Zuletzt bearbeitet 21.11.2024 06:10:23
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and mul...
CVE-2021-26993
- EPSS 0.45%
- Veröffentlicht 11.06.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:57:09
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to cause a partial Denial of Service (DoS) to the web server.
CVE-2021-26995
- EPSS 0.98%
- Veröffentlicht 11.06.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:57:09
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow privileged attackers to execute arbitrary code.
CVE-2021-26996
- EPSS 0.26%
- Veröffentlicht 11.06.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:57:09
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in...
CVE-2021-26997
- EPSS 0.24%
- Veröffentlicht 11.06.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:57:09
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information via error messaging which may aid in crafting more co...
CVE-2021-3522
- EPSS 0.11%
- Veröffentlicht 02.06.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:45
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
CVE-2021-33574
- EPSS 0.12%
- Veröffentlicht 25.05.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:09:07
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to...
CVE-2021-3517
- EPSS 0.09%
- Veröffentlicht 19.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:44
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-o...
- EPSS 0.21%
- Veröffentlicht 01.04.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:59:12
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps thems...
CVE-2021-28164
- EPSS 93.52%
- Veröffentlicht 01.04.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:59:13
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF...