CVE-2021-35368
- EPSS 0.42%
- Veröffentlicht 05.11.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:12:15
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
CVE-2021-3927
- EPSS 0.23%
- Veröffentlicht 05.11.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:47
vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3928
- EPSS 0.04%
- Veröffentlicht 05.11.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:47
vim is vulnerable to Use of Uninitialized Variable
CVE-2021-43400
- EPSS 0.17%
- Veröffentlicht 04.11.2021 23:15:10
- Zuletzt bearbeitet 04.11.2025 16:15:45
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
CVE-2021-43389
- EPSS 0.01%
- Veröffentlicht 04.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:08
An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.
CVE-2021-22960
- EPSS 0.23%
- Veröffentlicht 03.11.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:01
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
CVE-2021-40985
- EPSS 0.1%
- Veröffentlicht 03.11.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:11
A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.
CVE-2021-37148
- EPSS 1.01%
- Veröffentlicht 03.11.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:14:43
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.
CVE-2021-37149
- EPSS 1.01%
- Veröffentlicht 03.11.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:14:43
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
CVE-2021-38161
- EPSS 1.17%
- Veröffentlicht 03.11.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:31
Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks. This issue affects Apache Traffic Server 8.0.0 to 8.0.8.