CVE-2021-20308
- EPSS 0.55%
- Veröffentlicht 05.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:20
Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.
CVE-2021-1844
- EPSS 0.72%
- Veröffentlicht 02.04.2021 19:15:20
- Zuletzt bearbeitet 21.11.2024 05:45:13
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur 11.2.3. Processing maliciously crafted web content...
CVE-2021-1871
- EPSS 0.55%
- Veröffentlicht 02.04.2021 19:15:20
- Zuletzt bearbeitet 23.10.2025 18:01:41
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code exe...
CVE-2021-1788
- EPSS 0.58%
- Veröffentlicht 02.04.2021 18:15:21
- Zuletzt bearbeitet 21.11.2024 05:45:06
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Proc...
CVE-2020-10001
- EPSS 0.09%
- Veröffentlicht 02.04.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 04:54:37
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.
CVE-2021-30002
- EPSS 0.03%
- Veröffentlicht 02.04.2021 05:15:12
- Zuletzt bearbeitet 21.11.2024 06:03:12
An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.
CVE-2021-22876
- EPSS 0.06%
- Veröffentlicht 01.04.2021 18:15:12
- Zuletzt bearbeitet 09.06.2025 15:15:23
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically...
CVE-2021-22890
- EPSS 0.13%
- Veröffentlicht 01.04.2021 18:15:12
- Zuletzt bearbeitet 09.06.2025 15:15:24
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving fro...
CVE-2021-20296
- EPSS 0.12%
- Veröffentlicht 01.04.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:18
A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat ...
CVE-2021-3477
- EPSS 0.1%
- Veröffentlicht 31.03.2021 14:15:21
- Zuletzt bearbeitet 21.11.2024 06:21:38
There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, subsequently leading to an out-of-bounds read...