CVE-2021-40153
- EPSS 0.54%
- Veröffentlicht 27.08.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:23:40
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination dire...
CVE-2021-3713
- EPSS 0.03%
- Veröffentlicht 25.08.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 06:22:13
An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device emulation of QEMU in versions prior to 6.2.0-rc0. The device uses the guest supplied stream number unchecked, which can lead to out-of-bounds access to the UASDevice->data3 a...
CVE-2021-3605
- EPSS 0.08%
- Veröffentlicht 25.08.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:57
There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to appli...
CVE-2021-21840
- EPSS 0.25%
- Veröffentlicht 25.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:05
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input used to process an atom using the “saio” FOURCC code cause an integ...
CVE-2021-21841
- EPSS 0.25%
- Veröffentlicht 25.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:05
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when reading an atom using the 'sbgp' FOURCC code can cause an inte...
CVE-2021-21842
- EPSS 0.42%
- Veröffentlicht 25.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:05
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when processing an atom using the 'ss...
CVE-2021-21848
- EPSS 0.25%
- Veröffentlicht 25.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:06
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The library will actually reuse the parser for atoms with the “stsz” FOURCC code when parsing atoms ...
CVE-2021-21849
- EPSS 0.42%
- Veröffentlicht 25.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:06
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when the library encounters an atom u...
CVE-2021-21850
- EPSS 0.42%
- Veröffentlicht 25.08.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:06
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when the library encounters an atom u...
CVE-2021-21834
- EPSS 0.21%
- Veröffentlicht 25.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:04
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when decoding the atom for the “co64” FOURCC can cause an integer o...