CVE-2021-1871
- EPSS 0.86%
- Veröffentlicht 02.04.2021 19:15:20
- Zuletzt bearbeitet 23.10.2025 18:01:41
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code exe...
CVE-2021-1788
- EPSS 0.41%
- Veröffentlicht 02.04.2021 18:15:21
- Zuletzt bearbeitet 21.11.2024 05:45:06
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Proc...
CVE-2020-10001
- EPSS 0.09%
- Veröffentlicht 02.04.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 04:54:37
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.
CVE-2021-30002
- EPSS 0.03%
- Veröffentlicht 02.04.2021 05:15:12
- Zuletzt bearbeitet 21.11.2024 06:03:12
An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.
CVE-2021-22876
- EPSS 0.07%
- Veröffentlicht 01.04.2021 18:15:12
- Zuletzt bearbeitet 09.06.2025 15:15:23
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically...
CVE-2021-22890
- EPSS 0.09%
- Veröffentlicht 01.04.2021 18:15:12
- Zuletzt bearbeitet 09.06.2025 15:15:24
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving fro...
CVE-2021-20296
- EPSS 1.01%
- Veröffentlicht 01.04.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:18
A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat ...
CVE-2021-3477
- EPSS 0.51%
- Veröffentlicht 31.03.2021 14:15:21
- Zuletzt bearbeitet 21.11.2024 06:21:38
There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, subsequently leading to an out-of-bounds read...
CVE-2021-3478
- EPSS 0.51%
- Veröffentlicht 31.03.2021 14:15:21
- Zuletzt bearbeitet 21.11.2024 06:21:38
There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system ava...
CVE-2021-3479
- EPSS 0.48%
- Veröffentlicht 31.03.2021 14:15:21
- Zuletzt bearbeitet 21.11.2024 06:21:38
There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption of memory, resulting in an impact to system availabi...