CVE-2021-2144
- EPSS 3.15%
- Veröffentlicht 22.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:02:28
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network acces...
- EPSS 1.73%
- Veröffentlicht 22.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:02:28
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network acce...
- EPSS 0.18%
- Veröffentlicht 22.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:02:29
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols...
CVE-2021-29425
- EPSS 0.48%
- Veröffentlicht 13.04.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 06:01:04
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but ...
CVE-2021-20305
- EPSS 0.16%
- Veröffentlicht 05.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:19
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possi...
CVE-2021-3449
- EPSS 10.19%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but incl...
CVE-2019-19343
- EPSS 0.51%
- Veröffentlicht 23.03.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:36
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1...
CVE-2021-20231
- EPSS 0.92%
- Veröffentlicht 12.03.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:10
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
CVE-2021-22884
- EPSS 0.5%
- Veröffentlicht 03.03.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:50:50
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over ne...
CVE-2021-20220
- EPSS 0.31%
- Veröffentlicht 23.02.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:09
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an a...