CVE-2021-46143
- EPSS 4.09%
- Published 06.01.2022 04:15:07
- Last modified 05.05.2025 17:17:28
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
- EPSS 0.37%
- Published 01.01.2022 19:15:08
- Last modified 05.05.2025 17:17:28
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
- EPSS 94.36%
- Published 10.12.2021 10:15:09
- Last modified 08.08.2025 18:52:00
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An atta...
CVE-2021-43618
- EPSS 0.5%
- Published 15.11.2021 04:15:06
- Last modified 21.11.2024 06:29:31
GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.
CVE-2021-22096
- EPSS 0.22%
- Published 28.10.2021 16:15:07
- Last modified 21.11.2024 05:49:31
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
- EPSS 6.24%
- Published 20.10.2021 11:17:13
- Last modified 21.11.2024 06:12:40
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows hi...
CVE-2021-35618
- EPSS 0.32%
- Published 20.10.2021 11:17:12
- Last modified 21.11.2024 06:12:39
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical commun...
CVE-2021-35603
- EPSS 0.12%
- Published 20.10.2021 11:17:05
- Last modified 21.11.2024 06:12:37
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult ...
- EPSS 0.15%
- Published 20.10.2021 11:16:59
- Last modified 21.11.2024 06:12:35
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily ...
CVE-2021-35588
- EPSS 0.09%
- Published 20.10.2021 11:16:59
- Last modified 21.11.2024 06:12:35
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u311, 8u301; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit...