CVE-2021-3498
- EPSS 0.24%
- Veröffentlicht 19.04.2021 21:15:13
- Zuletzt bearbeitet 17.03.2026 15:52:33
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
CVE-2021-29458
- EPSS 0.1%
- Veröffentlicht 19.04.2021 19:15:18
- Zuletzt bearbeitet 21.11.2024 06:01:08
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used t...
CVE-2021-29457
- EPSS 1.51%
- Veröffentlicht 19.04.2021 19:15:17
- Zuletzt bearbeitet 21.11.2024 06:01:08
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to wr...
CVE-2021-31347
- EPSS 1.17%
- Veröffentlicht 16.04.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:05:28
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (writing outside a memory region created by mmap).
CVE-2021-31348
- EPSS 0.86%
- Veröffentlicht 16.04.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:05:28
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).
CVE-2021-29450
- EPSS 2.08%
- Veröffentlicht 15.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:01:07
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with ...
CVE-2021-29447
- EPSS 89.98%
- Veröffentlicht 15.04.2021 21:15:17
- Zuletzt bearbeitet 21.11.2024 06:01:07
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files i...
CVE-2021-20288
- EPSS 0.2%
- Veröffentlicht 15.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:17
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of ...
CVE-2021-31229
- EPSS 1.85%
- Veröffentlicht 15.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 06:05:20
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant.
CVE-2021-29338
- EPSS 0.09%
- Veröffentlicht 14.04.2021 14:15:14
- Zuletzt bearbeitet 03.11.2025 20:15:46
Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.