CVE-2021-4011
- EPSS 0.1%
- Veröffentlicht 17.12.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 06:36:43
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as sys...
CVE-2021-45098
- EPSS 0.65%
- Veröffentlicht 16.12.2021 05:15:08
- Zuletzt bearbeitet 03.11.2025 20:15:51
An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to injec...
CVE-2021-45095
- EPSS 0.04%
- Veröffentlicht 16.12.2021 04:15:06
- Zuletzt bearbeitet 21.11.2024 06:31:56
pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.
CVE-2021-45085
- EPSS 0.29%
- Veröffentlicht 16.12.2021 03:15:10
- Zuletzt bearbeitet 21.11.2024 06:31:55
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
CVE-2021-45086
- EPSS 0.21%
- Veröffentlicht 16.12.2021 03:15:10
- Zuletzt bearbeitet 21.11.2024 06:31:55
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
CVE-2021-45087
- EPSS 0.29%
- Veröffentlicht 16.12.2021 03:15:10
- Zuletzt bearbeitet 21.11.2024 06:31:55
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
CVE-2021-45088
- EPSS 0.29%
- Veröffentlicht 16.12.2021 03:15:10
- Zuletzt bearbeitet 21.11.2024 06:31:55
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
CVE-2021-45078
- EPSS 0.16%
- Veröffentlicht 15.12.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:31:54
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists b...
CVE-2021-0920
- EPSS 0.91%
- Veröffentlicht 15.12.2021 19:15:11
- Zuletzt bearbeitet 23.10.2025 14:53:26
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVE-2021-43113
- EPSS 2.63%
- Veröffentlicht 15.12.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:41
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.