CVE-2021-3478
- EPSS 0.1%
- Published 31.03.2021 14:15:21
- Last modified 21.11.2024 06:21:38
There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system ava...
CVE-2021-3479
- EPSS 0.1%
- Published 31.03.2021 14:15:21
- Last modified 21.11.2024 06:21:38
There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption of memory, resulting in an impact to system availabi...
CVE-2021-29647
- EPSS 0.1%
- Published 30.03.2021 21:15:14
- Last modified 21.11.2024 06:01:33
An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.
CVE-2021-29650
- EPSS 0.02%
- Published 30.03.2021 21:15:14
- Last modified 21.11.2024 06:01:34
An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assi...
CVE-2021-3475
- EPSS 0.11%
- Published 30.03.2021 18:15:18
- Last modified 21.11.2024 06:21:37
There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.
CVE-2021-3476
- EPSS 0.11%
- Published 30.03.2021 18:15:18
- Last modified 21.11.2024 06:21:38
A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.
CVE-2021-3474
- EPSS 0.11%
- Published 30.03.2021 18:15:17
- Last modified 21.11.2024 06:21:37
There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
CVE-2021-21409
- EPSS 4.98%
- Published 30.03.2021 15:15:14
- Last modified 21.11.2024 05:48:17
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerabi...
CVE-2021-29376
- EPSS 3.61%
- Published 30.03.2021 07:15:12
- Last modified 21.11.2024 06:01:00
ircII before 20210314 allows remote attackers to cause a denial of service (segmentation fault and client crash, disconnecting the victim from an IRC server) via a crafted CTCP UTC message.
CVE-2021-23358
- EPSS 1.43%
- Published 29.03.2021 14:15:18
- Last modified 21.11.2024 05:51:34
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.