CVE-2021-21853
- EPSS 0.52%
- Veröffentlicht 18.08.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:06
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arit...
CVE-2021-21854
- EPSS 0.52%
- Veröffentlicht 18.08.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:06
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arit...
CVE-2021-21855
- EPSS 0.52%
- Veröffentlicht 18.08.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:07
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arit...
CVE-2021-39240
- EPSS 0.07%
- Veröffentlicht 17.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:18:59
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It does not ensure that the scheme and path portions of a URI have the expected characters. For example, the authority field (as observed on a target HTTP/...
CVE-2021-39241
- EPSS 0.44%
- Veröffentlicht 17.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:18:59
An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this ...
CVE-2021-39242
- EPSS 0.47%
- Veröffentlicht 17.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:18:59
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.
CVE-2021-21859
- EPSS 0.61%
- Veröffentlicht 16.08.2021 20:15:48
- Zuletzt bearbeitet 21.11.2024 05:49:07
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The stri_box_read function is used when processing atoms using the 'stri' FOURCC code. An attacker...
CVE-2021-21860
- EPSS 0.46%
- Veröffentlicht 16.08.2021 20:15:48
- Zuletzt bearbeitet 21.11.2024 05:49:07
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based...
CVE-2021-21861
- EPSS 0.42%
- Veröffentlicht 16.08.2021 20:15:48
- Zuletzt bearbeitet 21.11.2024 05:49:07
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. When processing the 'hdlr' FOURCC code, a specially crafted MPEG-4 input can cause an improper mem...
CVE-2021-22939
- EPSS 0.13%
- Veröffentlicht 16.08.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:50:58
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.