CVE-2021-29264
- EPSS 0.1%
- Veröffentlicht 26.03.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 06:00:54
An issue was discovered in the Linux kernel through 5.11.10. drivers/net/ethernet/freescale/gianfar.c in the Freescale Gianfar Ethernet driver allows attackers to cause a system crash because a negative fragment size is calculated in situations invol...
CVE-2021-29265
- EPSS 0.11%
- Veröffentlicht 26.03.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 06:00:54
An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows attackers to cause a denial of service (GPF) because the stub-up sequence has race conditions during an update of the local and share...
CVE-2021-3449
- EPSS 13.18%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but incl...
- EPSS 1.5%
- Veröffentlicht 25.03.2021 10:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:42
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version ...
CVE-2021-3409
- EPSS 0.05%
- Veröffentlicht 23.03.2021 21:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:26
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest ...
CVE-2021-3392
- EPSS 0.13%
- Veröffentlicht 23.03.2021 20:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:24
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This fl...
CVE-2021-3444
- EPSS 0.09%
- Veröffentlicht 23.03.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:32
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel me...
CVE-2021-20270
- EPSS 0.12%
- Veröffentlicht 23.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:15
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
CVE-2021-21347
- EPSS 2.89%
- Veröffentlicht 23.03.2021 00:15:13
- Zuletzt bearbeitet 23.05.2025 17:41:49
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processe...
CVE-2021-21348
- EPSS 0.2%
- Veröffentlicht 23.03.2021 00:15:13
- Zuletzt bearbeitet 23.05.2025 17:42:08
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is aff...