CVE-2021-35517
- EPSS 1.32%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:25
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services th...
CVE-2021-36090
- EPSS 0.74%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:08
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services th...
CVE-2021-3517
- EPSS 0.11%
- Veröffentlicht 19.05.2021 14:15:07
- Zuletzt bearbeitet 02.12.2025 22:16:07
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-o...
CVE-2021-3518
- EPSS 0.25%
- Veröffentlicht 18.05.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:44
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, inte...
CVE-2021-3537
- EPSS 0.11%
- Veröffentlicht 14.05.2021 20:15:16
- Zuletzt bearbeitet 21.11.2024 06:21:47
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could...
CVE-2021-2216
- EPSS 0.58%
- Veröffentlicht 22.04.2021 22:15:14
- Zuletzt bearbeitet 21.11.2024 06:02:38
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Multichannel Framework). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker wi...
CVE-2021-2219
- EPSS 0.14%
- Veröffentlicht 22.04.2021 22:15:14
- Zuletzt bearbeitet 21.11.2024 06:02:39
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows low privileged attacker with network access vi...
CVE-2021-3449
- EPSS 9.86%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but incl...
CVE-2021-3450
- EPSS 0.5%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly ...
CVE-2021-21345
- EPSS 88.09%
- Veröffentlicht 23.03.2021 00:15:12
- Zuletzt bearbeitet 23.05.2025 17:41:10
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the proc...