CVE-2021-29647
- EPSS 0.09%
- Veröffentlicht 30.03.2021 21:15:14
- Zuletzt bearbeitet 21.11.2024 06:01:33
An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.
CVE-2021-29650
- EPSS 0.02%
- Veröffentlicht 30.03.2021 21:15:14
- Zuletzt bearbeitet 21.11.2024 06:01:34
An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assi...
CVE-2021-3475
- EPSS 0.65%
- Veröffentlicht 30.03.2021 18:15:18
- Zuletzt bearbeitet 21.11.2024 06:21:37
There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.
CVE-2021-3476
- EPSS 1.01%
- Veröffentlicht 30.03.2021 18:15:18
- Zuletzt bearbeitet 21.11.2024 06:21:38
A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.
CVE-2021-3474
- EPSS 1.01%
- Veröffentlicht 30.03.2021 18:15:17
- Zuletzt bearbeitet 21.11.2024 06:21:37
There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
CVE-2021-21409
- EPSS 3.16%
- Veröffentlicht 30.03.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:48:17
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerabi...
CVE-2021-29376
- EPSS 4.29%
- Veröffentlicht 30.03.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 06:01:00
ircII before 20210314 allows remote attackers to cause a denial of service (segmentation fault and client crash, disconnecting the victim from an IRC server) via a crafted CTCP UTC message.
CVE-2021-23358
- EPSS 1.43%
- Veröffentlicht 29.03.2021 14:15:18
- Zuletzt bearbeitet 03.11.2025 22:15:47
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
CVE-2021-29264
- EPSS 0.1%
- Veröffentlicht 26.03.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 06:00:54
An issue was discovered in the Linux kernel through 5.11.10. drivers/net/ethernet/freescale/gianfar.c in the Freescale Gianfar Ethernet driver allows attackers to cause a system crash because a negative fragment size is calculated in situations invol...
CVE-2021-29265
- EPSS 0.11%
- Veröffentlicht 26.03.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 06:00:54
An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows attackers to cause a denial of service (GPF) because the stub-up sequence has race conditions during an update of the local and share...