- EPSS 0.1%
- Veröffentlicht 01.02.2021 04:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:21
nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID...
CVE-2020-17380
- EPSS 0.08%
- Veröffentlicht 30.01.2021 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:58
A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via the sdhci_sdma_transfer_multi_blocks() routine in hw/sd/sdhci.c. A guest user or process co...
CVE-2021-3347
- EPSS 0.21%
- Veröffentlicht 29.01.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:21:21
An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.
CVE-2021-3326
- EPSS 0.23%
- Veröffentlicht 27.01.2021 20:15:14
- Zuletzt bearbeitet 09.06.2025 16:15:32
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of ser...
CVE-2021-26117
- EPSS 16.3%
- Veröffentlicht 27.01.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:55:53
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is...
CVE-2021-3156
- EPSS 92.19%
- Veröffentlicht 26.01.2021 21:15:12
- Zuletzt bearbeitet 22.10.2025 00:17:43
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
CVE-2021-3114
- EPSS 0.04%
- Veröffentlicht 26.01.2021 18:16:27
- Zuletzt bearbeitet 21.11.2024 06:20:54
In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.
CVE-2020-36225
- EPSS 0.7%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:05
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
CVE-2020-36226
- EPSS 0.57%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:05
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
CVE-2020-36227
- EPSS 60.34%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:05
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.