CVE-2021-38173
- EPSS 0.2%
- Published 07.08.2021 19:15:06
- Last modified 21.11.2024 06:16:33
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.
CVE-2021-38166
- EPSS 0.1%
- Published 07.08.2021 18:15:07
- Last modified 21.11.2024 06:16:32
In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.
CVE-2021-38165
- EPSS 4.28%
- Published 07.08.2021 18:15:06
- Last modified 21.11.2024 06:16:32
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
CVE-2021-38160
- EPSS 0.07%
- Published 07.08.2021 04:15:06
- Last modified 05.05.2025 14:12:40
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is...
CVE-2021-3655
- EPSS 0.02%
- Published 05.08.2021 21:15:13
- Last modified 21.11.2024 06:22:05
A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
CVE-2021-3566
- EPSS 0.1%
- Published 05.08.2021 21:15:12
- Last modified 21.11.2024 06:21:51
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will...
CVE-2021-3580
- EPSS 0.04%
- Published 05.08.2021 21:15:12
- Last modified 21.11.2024 06:21:53
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
CVE-2021-22924
- EPSS 0.75%
- Published 05.08.2021 21:15:11
- Last modified 09.06.2025 15:15:24
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the invo...
CVE-2021-3679
- EPSS 1.41%
- Published 05.08.2021 20:15:09
- Last modified 21.11.2024 06:22:08
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw ...
CVE-2021-3682
- EPSS 0.43%
- Published 05.08.2021 20:15:09
- Last modified 21.11.2024 06:22:09
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this fla...