CVE-2021-43174
- EPSS 0.72%
- Veröffentlicht 09.11.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:46
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP...
CVE-2021-43114
- EPSS 0.57%
- Veröffentlicht 09.11.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:42
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
CVE-2021-41771
- EPSS 0.84%
- Veröffentlicht 08.11.2021 06:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:44
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
CVE-2021-35368
- EPSS 0.42%
- Veröffentlicht 05.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:12:15
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
CVE-2021-3927
- EPSS 0.22%
- Veröffentlicht 05.11.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:47
vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3928
- EPSS 0.04%
- Veröffentlicht 05.11.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:47
vim is vulnerable to Use of Uninitialized Variable
CVE-2021-43400
- EPSS 0.17%
- Veröffentlicht 04.11.2021 23:15:10
- Zuletzt bearbeitet 04.11.2025 16:15:45
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
CVE-2021-43389
- EPSS 0.01%
- Veröffentlicht 04.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:08
An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.
CVE-2021-22960
- EPSS 0.23%
- Veröffentlicht 03.11.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:01
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
CVE-2021-40985
- EPSS 0.1%
- Veröffentlicht 03.11.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:11
A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.