CVE-2021-37977
- EPSS 0.77%
- Veröffentlicht 02.11.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:10
Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37978
- EPSS 2.29%
- Veröffentlicht 02.11.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:10
Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37979
- EPSS 1.71%
- Veröffentlicht 02.11.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:10
heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-37980
- EPSS 0.31%
- Veröffentlicht 02.11.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:11
Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.
CVE-2021-3903
- EPSS 0.37%
- Veröffentlicht 27.10.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:44
vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-25219
- EPSS 0.96%
- Veröffentlicht 27.10.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:54:34
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken ...
CVE-2021-41182
- EPSS 24.08%
- Veröffentlicht 26.10.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:25:41
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any str...
CVE-2021-41183
- EPSS 2.92%
- Veröffentlicht 26.10.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:25:42
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The v...
- EPSS 0.13%
- Veröffentlicht 25.10.2021 06:15:06
- Zuletzt bearbeitet 21.11.2024 05:48:52
In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the c...
CVE-2021-42715
- EPSS 0.16%
- Veröffentlicht 21.10.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:01
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb...