CVE-2020-35662
- EPSS 0.75%
- Veröffentlicht 27.02.2021 05:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:47
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
CVE-2021-25281
- EPSS 93.85%
- Veröffentlicht 27.02.2021 05:15:13
- Zuletzt bearbeitet 21.11.2024 05:54:40
An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.
CVE-2021-25282
- EPSS 91.29%
- Veröffentlicht 27.02.2021 05:15:13
- Zuletzt bearbeitet 21.11.2024 05:54:40
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
CVE-2021-25283
- EPSS 10.04%
- Veröffentlicht 27.02.2021 05:15:13
- Zuletzt bearbeitet 21.11.2024 05:54:40
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
CVE-2020-27618
- EPSS 0.05%
- Veröffentlicht 26.02.2021 23:15:11
- Zuletzt bearbeitet 09.06.2025 16:15:31
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an i...
CVE-2021-27803
- EPSS 0.33%
- Veröffentlicht 26.02.2021 23:15:11
- Zuletzt bearbeitet 18.12.2025 15:15:48
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacke...
CVE-2020-27223
- EPSS 33.82%
- Veröffentlicht 26.02.2021 22:15:19
- Zuletzt bearbeitet 20.08.2025 10:15:27
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) ...
CVE-2021-23978
- EPSS 1.22%
- Veröffentlicht 26.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:52:08
Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. T...
CVE-2021-23961
- EPSS 0.63%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:06
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
CVE-2021-21330
- EPSS 0.49%
- Veröffentlicht 26.02.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:02
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a differe...