CVE-2021-41229
- EPSS 0.04%
- Veröffentlicht 12.11.2021 23:15:08
- Zuletzt bearbeitet 04.11.2025 16:15:44
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory l...
CVE-2021-43331
- EPSS 0.15%
- Veröffentlicht 12.11.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:05
In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.
CVE-2021-43332
- EPSS 0.12%
- Veröffentlicht 12.11.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:06
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.
CVE-2021-3911
- EPSS 0.55%
- Veröffentlicht 11.11.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:45
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
CVE-2021-3912
- EPSS 0.55%
- Veröffentlicht 11.11.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:45
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
CVE-2021-3907
- EPSS 1.47%
- Veröffentlicht 11.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:45
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could all...
CVE-2021-3908
- EPSS 0.29%
- Veröffentlicht 11.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:45
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
CVE-2021-3909
- EPSS 0.74%
- Veröffentlicht 11.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:45
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before ...
CVE-2021-3910
- EPSS 0.56%
- Veröffentlicht 11.11.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:45
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
CVE-2021-43173
- EPSS 0.44%
- Veröffentlicht 09.11.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:46
In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routina...