CVE-2021-38114
- EPSS 0.11%
- Veröffentlicht 04.08.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:25
libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-2013-0868.
CVE-2021-30560
- EPSS 0.09%
- Veröffentlicht 03.08.2021 19:15:08
- Zuletzt bearbeitet 05.05.2025 17:17:03
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-33196
- EPSS 0.02%
- Veröffentlicht 02.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:29
In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic.
CVE-2021-34556
- EPSS 0.04%
- Veröffentlicht 02.08.2021 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:10:40
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory l...
CVE-2021-35477
- EPSS 0.04%
- Veröffentlicht 02.08.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:21
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a st...
CVE-2021-35472
- EPSS 0.48%
- Veröffentlicht 30.07.2021 14:15:17
- Zuletzt bearbeitet 21.11.2024 06:12:20
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two dif...
- EPSS 0.35%
- Veröffentlicht 30.07.2021 14:15:16
- Zuletzt bearbeitet 21.11.2024 06:06:14
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
CVE-2021-32558
- EPSS 2.79%
- Veröffentlicht 30.07.2021 14:15:16
- Zuletzt bearbeitet 21.11.2024 06:07:16
An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported med...
CVE-2021-32610
- EPSS 2.98%
- Veröffentlicht 30.07.2021 14:15:16
- Zuletzt bearbeitet 21.11.2024 06:07:22
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
CVE-2021-31292
- EPSS 0.55%
- Veröffentlicht 26.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:05:24
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.