CVE-2021-39191
- EPSS 0.33%
- Veröffentlicht 03.09.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:18:50
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO...
CVE-2021-40491
- EPSS 0.34%
- Veröffentlicht 03.09.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:24:14
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
- EPSS 0.04%
- Veröffentlicht 03.09.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:24:14
A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
CVE-2021-39847
- EPSS 0.31%
- Veröffentlicht 01.09.2021 15:15:12
- Zuletzt bearbeitet 03.11.2025 20:15:49
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must...
CVE-2021-36057
- EPSS 0.04%
- Veröffentlicht 01.09.2021 15:15:11
- Zuletzt bearbeitet 03.11.2025 20:15:49
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local a...
CVE-2021-36058
- EPSS 0.31%
- Veröffentlicht 01.09.2021 15:15:11
- Zuletzt bearbeitet 03.11.2025 20:15:49
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potentially resulting in application-level denial of service in the context of the current user. Exploitation requires user interaction in that a victim mus...
CVE-2021-36064
- EPSS 0.72%
- Veröffentlicht 01.09.2021 15:15:11
- Zuletzt bearbeitet 03.11.2025 20:15:49
XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope...
CVE-2021-36045
- EPSS 0.3%
- Veröffentlicht 01.09.2021 15:15:10
- Zuletzt bearbeitet 03.11.2025 20:15:47
XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of thi...
CVE-2021-36046
- EPSS 0.35%
- Veröffentlicht 01.09.2021 15:15:10
- Zuletzt bearbeitet 03.11.2025 20:15:47
XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
CVE-2021-36047
- EPSS 0.55%
- Veröffentlicht 01.09.2021 15:15:10
- Zuletzt bearbeitet 03.11.2025 20:15:48
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must ...