CVE-2021-2341
- EPSS 0.32%
- Veröffentlicht 21.07.2021 15:15:17
- Zuletzt bearbeitet 27.05.2025 16:47:32
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. ...
CVE-2020-19609
- EPSS 0.45%
- Veröffentlicht 21.07.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:09:15
Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.
CVE-2021-33909
- EPSS 2.22%
- Veröffentlicht 20.07.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:09:45
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
CVE-2021-33910
- EPSS 0.08%
- Veröffentlicht 20.07.2021 19:15:09
- Zuletzt bearbeitet 09.06.2025 16:15:32
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
CVE-2021-3246
- EPSS 0.81%
- Veröffentlicht 20.07.2021 15:15:11
- Zuletzt bearbeitet 21.11.2024 06:21:09
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
CVE-2021-22235
- EPSS 0.76%
- Veröffentlicht 20.07.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:45
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file
CVE-2019-25051
- EPSS 0.05%
- Veröffentlicht 20.07.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:50
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
CVE-2020-36421
- EPSS 0.57%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 03.12.2025 16:15:53
An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
CVE-2020-36422
- EPSS 0.51%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.
CVE-2020-36423
- EPSS 0.49%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.