- EPSS 0.15%
- Veröffentlicht 20.10.2021 11:16:37
- Zuletzt bearbeitet 21.11.2024 06:12:32
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploit...
CVE-2021-35560
- EPSS 0.64%
- Veröffentlicht 20.10.2021 11:16:35
- Zuletzt bearbeitet 21.11.2024 06:12:31
Vulnerability in the Java SE product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to...
- EPSS 0.16%
- Veröffentlicht 20.10.2021 11:16:35
- Zuletzt bearbeitet 21.11.2024 06:12:31
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Utility). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily ...
- EPSS 0.12%
- Veröffentlicht 20.10.2021 11:16:34
- Zuletzt bearbeitet 21.11.2024 06:12:31
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily ex...
- EPSS 0.14%
- Veröffentlicht 20.10.2021 11:16:33
- Zuletzt bearbeitet 21.11.2024 06:12:30
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily ex...
CVE-2021-35550
- EPSS 0.08%
- Veröffentlicht 20.10.2021 11:16:31
- Zuletzt bearbeitet 21.11.2024 06:12:29
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to e...
CVE-2021-3711
- EPSS 2.75%
- Veröffentlicht 24.08.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:12
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen...
CVE-2021-3712
- EPSS 0.82%
- Veröffentlicht 24.08.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:13
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the s...
CVE-2021-35942
- EPSS 1.2%
- Veröffentlicht 22.07.2021 18:15:23
- Zuletzt bearbeitet 01.05.2025 18:10:02
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of in...
CVE-2021-34429
- EPSS 93.8%
- Veröffentlicht 15.07.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:10:23
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerabilit...