CVE-2021-32490
- EPSS 0.1%
- Published 24.06.2021 19:15:08
- Last modified 21.11.2024 06:07:08
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences.
CVE-2021-32491
- EPSS 0.28%
- Published 24.06.2021 19:15:08
- Last modified 21.11.2024 06:07:08
A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.
CVE-2021-32492
- EPSS 0.28%
- Published 24.06.2021 19:15:08
- Last modified 21.11.2024 06:07:08
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to application crash and other consequences.
CVE-2021-32493
- EPSS 0.29%
- Published 24.06.2021 19:15:08
- Last modified 21.11.2024 06:07:08
A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences.
CVE-2021-33624
- EPSS 0.71%
- Published 23.06.2021 16:15:07
- Last modified 21.11.2024 06:09:13
In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6...
CVE-2021-34428
- EPSS 0.86%
- Published 22.06.2021 15:15:16
- Last modified 21.11.2024 06:10:23
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and mul...
CVE-2021-0561
- EPSS 0.02%
- Published 22.06.2021 11:15:08
- Last modified 21.11.2024 05:42:55
In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ...
CVE-2020-18442
- EPSS 0.06%
- Published 18.06.2021 15:15:08
- Last modified 10.07.2025 15:44:54
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".
CVE-2021-33813
- EPSS 0.08%
- Published 16.06.2021 12:15:12
- Last modified 21.11.2024 06:09:37
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
CVE-2021-30547
- EPSS 0.97%
- Published 15.06.2021 22:15:08
- Last modified 21.11.2024 06:04:09
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.