CVE-2021-3541
- EPSS 0.07%
- Published 09.07.2021 17:15:07
- Last modified 21.11.2024 06:21:48
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
CVE-2021-3612
- EPSS 0.09%
- Published 09.07.2021 11:15:09
- Last modified 21.11.2024 06:21:58
An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privi...
CVE-2021-28691
- EPSS 0.04%
- Published 29.06.2021 12:15:08
- Last modified 21.11.2024 06:00:09
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malfor...
CVE-2020-28097
- EPSS 0.16%
- Published 24.06.2021 12:15:07
- Last modified 21.11.2024 05:22:21
The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85.
CVE-2021-22901
- EPSS 0.34%
- Published 11.06.2021 16:15:11
- Last modified 21.11.2024 05:50:52
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentia...
CVE-2021-22897
- EPSS 1.08%
- Published 11.06.2021 16:15:10
- Last modified 21.11.2024 05:50:51
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" ...
CVE-2020-13938
- EPSS 0.28%
- Published 10.06.2021 07:15:07
- Last modified 21.11.2024 05:02:11
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
CVE-2021-26691
- EPSS 42.56%
- Published 10.06.2021 07:15:07
- Last modified 21.11.2024 05:56:41
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
CVE-2020-8670
- EPSS 0.05%
- Published 09.06.2021 19:15:09
- Last modified 21.11.2024 05:39:13
Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2020-8700
- EPSS 0.24%
- Published 09.06.2021 19:15:09
- Last modified 21.11.2024 05:39:17
Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.