CVE-2021-3778
- EPSS 0.39%
- Published 15.09.2021 08:15:06
- Last modified 21.11.2024 06:22:24
vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-41072
- EPSS 3.59%
- Published 14.09.2021 01:15:07
- Last modified 21.11.2024 06:25:22
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a fi...
CVE-2021-41054
- EPSS 0.58%
- Published 13.09.2021 21:15:09
- Last modified 21.11.2024 06:25:21
tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.
CVE-2021-39200
- EPSS 1.77%
- Published 09.09.2021 22:15:09
- Last modified 21.11.2024 06:18:52
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like no...
CVE-2021-39201
- EPSS 0.41%
- Published 09.09.2021 22:15:09
- Last modified 21.11.2024 06:18:53
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. Thi...
CVE-2020-19144
- EPSS 1.51%
- Published 09.09.2021 15:15:08
- Last modified 21.11.2024 05:08:58
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.
CVE-2020-19143
- EPSS 0.97%
- Published 09.09.2021 15:15:07
- Last modified 21.11.2024 05:08:58
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.
CVE-2021-3761
- EPSS 0.45%
- Published 09.09.2021 14:15:09
- Last modified 21.11.2024 06:22:21
Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Clou...
CVE-2021-40346
- EPSS 92.83%
- Published 08.09.2021 17:15:12
- Last modified 21.11.2024 06:23:54
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
CVE-2021-21897
- EPSS 1.7%
- Published 08.09.2021 16:15:07
- Last modified 21.11.2024 05:49:12
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerabil...