CVE-2021-26937
- EPSS 4.06%
- Veröffentlicht 09.02.2021 20:15:14
- Zuletzt bearbeitet 09.05.2025 20:15:36
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
CVE-2021-21148
- EPSS 22.3%
- Veröffentlicht 09.02.2021 16:15:12
- Zuletzt bearbeitet 24.10.2025 21:02:10
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-26675
- EPSS 0.14%
- Veröffentlicht 09.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:56:39
A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.
CVE-2021-26676
- EPSS 0.1%
- Veröffentlicht 09.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:56:39
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.
- EPSS 0.05%
- Veröffentlicht 08.02.2021 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:01
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
CVE-2021-21290
- EPSS 0.02%
- Veröffentlicht 08.02.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:56
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems inv...
CVE-2021-20176
- EPSS 0.07%
- Veröffentlicht 06.02.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:04
A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an attacker who submits a crafted file that is processed by ImageMagick to trigger undefined behavior through a division by zero. The highest threat fro...
CVE-2021-21289
- EPSS 2.5%
- Veröffentlicht 02.02.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:56
Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allow for OS commands to be inject...
CVE-2021-21285
- EPSS 0.14%
- Veröffentlicht 02.02.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:56
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
CVE-2021-21284
- EPSS 0.02%
- Veröffentlicht 02.02.2021 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:47:55
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace...