CVE-2021-23961
- EPSS 0.63%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:06
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
CVE-2021-21330
- EPSS 0.49%
- Veröffentlicht 26.02.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:02
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a differe...
CVE-2021-23973
- EPSS 0.53%
- Veröffentlicht 26.02.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:07
When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and...
CVE-2021-23968
- EPSS 0.27%
- Veröffentlicht 26.02.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:52:07
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such...
CVE-2021-23969
- EPSS 0.76%
- Veröffentlicht 26.02.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:52:07
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down ...
CVE-2021-20203
- EPSS 0.03%
- Veröffentlicht 25.02.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:46:07
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to cra...
CVE-2020-11987
- EPSS 1.36%
- Veröffentlicht 24.02.2021 18:15:11
- Zuletzt bearbeitet 03.11.2025 20:15:42
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arb...
CVE-2021-27645
- EPSS 0.04%
- Veröffentlicht 24.02.2021 15:15:13
- Zuletzt bearbeitet 09.06.2025 15:15:25
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the loc...
CVE-2021-3407
- EPSS 0.65%
- Veröffentlicht 23.02.2021 23:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:25
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
CVE-2021-3410
- EPSS 0.12%
- Veröffentlicht 23.02.2021 23:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:26
A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.