CVE-2021-21346
- EPSS 3.97%
- Veröffentlicht 23.03.2021 00:15:12
- Zuletzt bearbeitet 23.05.2025 17:41:29
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processe...
CVE-2021-21267
- EPSS 0.87%
- Veröffentlicht 19.03.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:53
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example `a@0.0.0.0.0.0.0.0...
CVE-2020-4976
- EPSS 0.09%
- Veröffentlicht 11.03.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:29
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469.
CVE-2020-5024
- EPSS 1.61%
- Veröffentlicht 11.03.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:34
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the SSL handshake response. IBM X-Force ID: 193660.
CVE-2020-5025
- EPSS 0.31%
- Veröffentlicht 11.03.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:34
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system ...
CVE-2021-22884
- EPSS 0.27%
- Veröffentlicht 03.03.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:50:50
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over ne...
CVE-2021-26296
- EPSS 0.32%
- Veröffentlicht 19.02.2021 09:15:13
- Zuletzt bearbeitet 21.11.2024 05:56:02
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, i...
CVE-2021-23841
- EPSS 0.67%
- Veröffentlicht 16.02.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:51:55
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while...
CVE-2021-2122
- EPSS 0.2%
- Veröffentlicht 20.01.2021 15:15:54
- Zuletzt bearbeitet 21.11.2024 06:02:25
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols...
CVE-2021-2087
- EPSS 0.09%
- Veröffentlicht 20.01.2021 15:15:51
- Zuletzt bearbeitet 21.11.2024 06:02:21
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MyS...