CVE-2020-35653
- EPSS 0.29%
- Veröffentlicht 12.01.2021 09:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:46
In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.
CVE-2021-0308
- EPSS 0.08%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVE-2020-26298
- EPSS 0.33%
- Veröffentlicht 11.01.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:19:47
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quot...
CVE-2021-21109
- EPSS 1.31%
- Veröffentlicht 08.01.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:47:35
Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-21110
- EPSS 23.07%
- Veröffentlicht 08.01.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:47:35
Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-21111
- EPSS 0.45%
- Veröffentlicht 08.01.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:47:35
Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVE-2021-21112
- EPSS 1.73%
- Veröffentlicht 08.01.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:47:35
Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21113
- EPSS 1.52%
- Veröffentlicht 08.01.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:47:35
Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21114
- EPSS 1.31%
- Veröffentlicht 08.01.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:47:35
Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21115
- EPSS 1.31%
- Veröffentlicht 08.01.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:47:35
User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.