CVE-2021-3596
- EPSS 0.17%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:21:55
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which ...
- EPSS 0.17%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:21:57
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a ...
- EPSS 0.04%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:21:58
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due ...
CVE-2021-3700
- EPSS 0.04%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:22:11
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or bl...
CVE-2021-44532
- EPSS 0.12%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:31:10
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an inje...
CVE-2021-44533
- EPSS 0.32%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:31:10
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a m...
CVE-2022-0544
- EPSS 0.17%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:38:53
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
CVE-2022-0545
- EPSS 0.29%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:38:53
An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender pr...
CVE-2022-0546
- EPSS 0.39%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:38:53
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
CVE-2022-25636
- EPSS 0.44%
- Published 24.02.2022 15:15:31
- Last modified 21.11.2024 06:52:29
net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.