CVE-2021-22931
- EPSS 0.74%
- Published 16.08.2021 19:15:13
- Last modified 21.11.2024 05:50:57
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostna...
CVE-2021-22926
- EPSS 0.51%
- Published 05.08.2021 21:15:11
- Last modified 21.11.2024 05:50:56
libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Trans...
CVE-2021-35942
- EPSS 1.2%
- Published 22.07.2021 18:15:23
- Last modified 01.05.2025 18:10:02
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of in...
CVE-2021-36222
- EPSS 4.66%
- Published 22.07.2021 18:15:23
- Last modified 21.11.2024 06:13:20
ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return valu...
CVE-2021-2389
- EPSS 0.49%
- Published 21.07.2021 15:15:41
- Last modified 21.11.2024 06:03:01
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via ...
CVE-2021-2372
- EPSS 0.23%
- Published 21.07.2021 15:15:32
- Last modified 21.11.2024 06:02:59
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via ...
CVE-2021-35043
- EPSS 0.33%
- Published 19.07.2021 15:15:07
- Last modified 21.11.2024 06:11:44
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
CVE-2021-35515
- EPSS 0.11%
- Published 13.07.2021 08:15:07
- Last modified 21.11.2024 06:12:25
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
CVE-2021-35516
- EPSS 0.28%
- Published 13.07.2021 08:15:07
- Last modified 21.11.2024 06:12:25
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services tha...
CVE-2021-35517
- EPSS 0.28%
- Published 13.07.2021 08:15:07
- Last modified 21.11.2024 06:12:25
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services th...