CVE-2021-22901
- EPSS 0.34%
- Veröffentlicht 11.06.2021 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:50:52
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentia...
CVE-2021-22897
- EPSS 1.08%
- Veröffentlicht 11.06.2021 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:50:51
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" ...
CVE-2021-28041
- EPSS 0.26%
- Veröffentlicht 05.03.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:59:01
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
CVE-2020-35507
- EPSS 0.05%
- Veröffentlicht 04.01.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:27:27
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat o...
CVE-2020-35496
- EPSS 0.05%
- Veröffentlicht 04.01.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:27:25
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to applicat...
CVE-2020-35494
- EPSS 0.21%
- Veröffentlicht 04.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:25
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to da...
CVE-2020-35495
- EPSS 0.21%
- Veröffentlicht 04.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:25
There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw ...
CVE-2020-35493
- EPSS 0.3%
- Veröffentlicht 04.01.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:24
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects ...
- EPSS 0.59%
- Veröffentlicht 28.11.2020 07:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:55
An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71.
CVE-2020-13817
- EPSS 0.38%
- Veröffentlicht 04.06.2020 13:15:11
- Zuletzt bearbeitet 05.05.2025 17:15:59
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated ...