CVE-2021-42528
- EPSS 0.12%
- Veröffentlicht 02.05.2022 23:15:07
- Zuletzt bearbeitet 03.11.2025 20:15:50
XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context ...
CVE-2021-42529
- EPSS 0.44%
- Veröffentlicht 02.05.2022 23:15:07
- Zuletzt bearbeitet 03.11.2025 20:15:50
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim mus...
CVE-2021-42530
- EPSS 0.44%
- Veröffentlicht 02.05.2022 23:15:07
- Zuletzt bearbeitet 03.11.2025 20:15:50
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim mus...
CVE-2021-42531
- EPSS 0.99%
- Veröffentlicht 02.05.2022 23:15:07
- Zuletzt bearbeitet 03.11.2025 20:15:50
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim mus...
CVE-2021-42532
- EPSS 0.51%
- Veröffentlicht 02.05.2022 23:15:07
- Zuletzt bearbeitet 03.11.2025 20:15:51
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim mus...
CVE-2021-46790
- EPSS 0.05%
- Veröffentlicht 02.05.2022 12:16:26
- Zuletzt bearbeitet 21.11.2024 06:34:43
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
CVE-2022-29970
- EPSS 0.6%
- Veröffentlicht 02.05.2022 05:15:06
- Zuletzt bearbeitet 04.11.2025 16:15:49
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
CVE-2022-25647
- EPSS 2.8%
- Veröffentlicht 01.05.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:52:30
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
CVE-2021-4206
- EPSS 0.16%
- Veröffentlicht 29.04.2022 17:15:20
- Zuletzt bearbeitet 21.03.2025 18:15:27
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious pri...
CVE-2021-4207
- EPSS 0.05%
- Veröffentlicht 29.04.2022 17:15:20
- Zuletzt bearbeitet 21.03.2025 18:15:28
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer ...