CVE-2021-3910
- EPSS 0.5%
- Veröffentlicht 11.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:45
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
CVE-2021-43173
- EPSS 0.44%
- Veröffentlicht 09.11.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:46
In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routina...
CVE-2021-43174
- EPSS 0.72%
- Veröffentlicht 09.11.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:46
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP...
CVE-2021-43114
- EPSS 0.57%
- Veröffentlicht 09.11.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:42
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
CVE-2021-41771
- EPSS 0.43%
- Veröffentlicht 08.11.2021 06:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:44
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
CVE-2021-35368
- EPSS 0.38%
- Veröffentlicht 05.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:12:15
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
CVE-2021-3927
- EPSS 0.16%
- Veröffentlicht 05.11.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:47
vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3928
- EPSS 0.06%
- Veröffentlicht 05.11.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:47
vim is vulnerable to Use of Uninitialized Variable
CVE-2021-43400
- EPSS 0.13%
- Veröffentlicht 04.11.2021 23:15:10
- Zuletzt bearbeitet 21.11.2024 06:29:10
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
CVE-2021-43389
- EPSS 0.01%
- Veröffentlicht 04.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:08
An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.