CVE-2021-36090
- EPSS 0.28%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:08
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services th...
CVE-2021-3541
- EPSS 0.07%
- Veröffentlicht 09.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:48
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
CVE-2021-34428
- EPSS 0.51%
- Veröffentlicht 22.06.2021 15:15:16
- Zuletzt bearbeitet 21.11.2024 06:10:23
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and mul...
CVE-2021-22901
- EPSS 0.34%
- Veröffentlicht 11.06.2021 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:50:52
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentia...
CVE-2021-28169
- EPSS 92.42%
- Veröffentlicht 09.06.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 05:59:14
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml...
CVE-2021-3522
- EPSS 0.11%
- Veröffentlicht 02.06.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:45
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
CVE-2021-3520
- EPSS 0.13%
- Veröffentlicht 02.06.2021 13:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:44
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. Th...
CVE-2020-25670
- EPSS 0.06%
- Veröffentlicht 26.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:18:25
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.
CVE-2020-25671
- EPSS 0.13%
- Veröffentlicht 26.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:18:25
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.
CVE-2020-25673
- EPSS 0.14%
- Veröffentlicht 26.05.2021 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:18:25
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.