CVE-2021-3506
- EPSS 0.14%
- Veröffentlicht 19.04.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:42
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system cras...
CVE-2021-3497
- EPSS 0.23%
- Veröffentlicht 19.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:41
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
CVE-2021-3498
- EPSS 0.24%
- Veröffentlicht 19.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:41
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
CVE-2021-29458
- EPSS 0.1%
- Veröffentlicht 19.04.2021 19:15:18
- Zuletzt bearbeitet 21.11.2024 06:01:08
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used t...
CVE-2021-29457
- EPSS 1.51%
- Veröffentlicht 19.04.2021 19:15:17
- Zuletzt bearbeitet 21.11.2024 06:01:08
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to wr...
CVE-2021-31347
- EPSS 1.17%
- Veröffentlicht 16.04.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:05:28
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (writing outside a memory region created by mmap).
CVE-2021-31348
- EPSS 0.86%
- Veröffentlicht 16.04.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:05:28
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).
CVE-2021-29450
- EPSS 2.08%
- Veröffentlicht 15.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:01:07
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with ...
CVE-2021-29447
- EPSS 89.98%
- Veröffentlicht 15.04.2021 21:15:17
- Zuletzt bearbeitet 21.11.2024 06:01:07
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files i...
CVE-2021-20288
- EPSS 0.18%
- Veröffentlicht 15.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:17
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of ...