CVE-2021-32272
- EPSS 0.26%
- Published 20.09.2021 16:15:10
- Last modified 21.11.2024 06:06:56
An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to cause Code Execution.
CVE-2021-32273
- EPSS 0.18%
- Published 20.09.2021 16:15:10
- Last modified 21.11.2024 06:06:56
An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to cause Code Execution.
CVE-2021-32274
- EPSS 0.2%
- Published 20.09.2021 16:15:10
- Last modified 21.11.2024 06:06:56
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows an attacker to cause code Execution.
CVE-2021-32276
- EPSS 0.13%
- Published 20.09.2021 16:15:10
- Last modified 21.11.2024 06:06:56
An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service.
CVE-2021-32277
- EPSS 0.2%
- Published 20.09.2021 16:15:10
- Last modified 21.11.2024 06:06:56
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an attacker to cause code Execution.
CVE-2021-32278
- EPSS 0.2%
- Published 20.09.2021 16:15:10
- Last modified 21.11.2024 06:06:57
An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an attacker to cause code Execution.
CVE-2021-32280
- EPSS 0.09%
- Published 20.09.2021 16:15:10
- Last modified 21.11.2024 06:06:57
An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.
CVE-2020-21913
- EPSS 0.12%
- Published 20.09.2021 14:15:08
- Last modified 21.11.2024 05:12:56
International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.
CVE-2021-38300
- EPSS 0.15%
- Published 20.09.2021 06:15:06
- Last modified 21.11.2024 06:16:45
arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF programs, allowing execution of arbitrary code within the kernel context. This occurs because conditional branches can...
CVE-2021-40690
- EPSS 0.34%
- Published 19.09.2021 18:15:07
- Last modified 21.11.2024 06:24:34
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacke...