CVE-2020-36424
- EPSS 0.14%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.
CVE-2020-36425
- EPSS 0.81%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
CVE-2020-36426
- EPSS 0.95%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).
CVE-2021-36773
- EPSS 1.51%
- Veröffentlicht 18.07.2021 04:15:08
- Zuletzt bearbeitet 21.11.2024 06:14:04
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss ...
CVE-2021-32743
- EPSS 0.35%
- Veröffentlicht 15.07.2021 16:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:48
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga...
CVE-2021-32739
- EPSS 0.3%
- Veröffentlicht 15.07.2021 15:15:08
- Zuletzt bearbeitet 03.11.2025 22:15:48
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege esca...
CVE-2021-36740
- EPSS 0.71%
- Veröffentlicht 14.07.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:59
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x be...
CVE-2021-24119
- EPSS 0.92%
- Veröffentlicht 14.07.2021 13:15:08
- Zuletzt bearbeitet 03.11.2025 20:15:45
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software runni...
CVE-2020-19716
- EPSS 0.84%
- Veröffentlicht 13.07.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:09:21
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
CVE-2021-34552
- EPSS 0.34%
- Veröffentlicht 13.07.2021 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:10:39
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.