CVE-2021-32672
- EPSS 0.29%
- Veröffentlicht 04.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:30
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions o...
CVE-2021-32628
- EPSS 0.59%
- Veröffentlicht 04.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:24
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnera...
CVE-2021-32627
- EPSS 0.8%
- Veröffentlicht 04.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:24
Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves changing the d...
CVE-2021-32626
- EPSS 1.17%
- Veröffentlicht 04.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:24
Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result...
CVE-2021-28169
- EPSS 92.42%
- Veröffentlicht 09.06.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 05:59:14
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml...
CVE-2021-22118
- EPSS 0.19%
- Veröffentlicht 27.05.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:32
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or ...
CVE-2020-27223
- EPSS 33.82%
- Veröffentlicht 26.02.2021 22:15:19
- Zuletzt bearbeitet 20.08.2025 10:15:27
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) ...