CVE-2021-23978
- EPSS 0.66%
- Veröffentlicht 26.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:52:08
Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. T...
CVE-2021-23961
- EPSS 0.79%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:06
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
CVE-2021-21330
- EPSS 0.49%
- Veröffentlicht 26.02.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:02
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a differe...
CVE-2021-23973
- EPSS 0.72%
- Veröffentlicht 26.02.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:07
When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and...
CVE-2021-23968
- EPSS 0.36%
- Veröffentlicht 26.02.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:52:07
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such...
CVE-2021-23969
- EPSS 1.02%
- Veröffentlicht 26.02.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:52:07
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down ...
CVE-2021-20203
- EPSS 0.03%
- Veröffentlicht 25.02.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:46:07
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to cra...
CVE-2020-11987
- EPSS 1.36%
- Veröffentlicht 24.02.2021 18:15:11
- Zuletzt bearbeitet 03.11.2025 20:15:42
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arb...
CVE-2021-27645
- EPSS 0.04%
- Veröffentlicht 24.02.2021 15:15:13
- Zuletzt bearbeitet 09.06.2025 15:15:25
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the loc...
CVE-2021-3407
- EPSS 1.19%
- Veröffentlicht 23.02.2021 23:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:25
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.