CVE-2021-20204
- EPSS 1.96%
- Veröffentlicht 06.05.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:07
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata...
CVE-2021-31542
- EPSS 6.38%
- Veröffentlicht 05.05.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:05:52
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
CVE-2021-20254
- EPSS 0.31%
- Veröffentlicht 05.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:13
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negativ...
CVE-2021-21227
- EPSS 3.18%
- Veröffentlicht 30.04.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:49
Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21228
- EPSS 0.65%
- Veröffentlicht 30.04.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:49
Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
CVE-2021-21229
- EPSS 0.86%
- Veröffentlicht 30.04.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:49
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVE-2021-21230
- EPSS 3.61%
- Veröffentlicht 30.04.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:49
Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21231
- EPSS 1.95%
- Veröffentlicht 30.04.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:49
Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21232
- EPSS 1.71%
- Veröffentlicht 30.04.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:49
Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21233
- EPSS 2.33%
- Veröffentlicht 30.04.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:49
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.