CVE-2021-21290
- EPSS 0.03%
- Veröffentlicht 08.02.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:56
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems inv...
CVE-2021-20176
- EPSS 0.13%
- Veröffentlicht 06.02.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:04
A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an attacker who submits a crafted file that is processed by ImageMagick to trigger undefined behavior through a division by zero. The highest threat fro...
CVE-2021-21289
- EPSS 2.5%
- Veröffentlicht 02.02.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:56
Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allow for OS commands to be inject...
CVE-2021-21285
- EPSS 0.35%
- Veröffentlicht 02.02.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:56
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
CVE-2021-21284
- EPSS 0.02%
- Veröffentlicht 02.02.2021 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:47:55
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace...
- EPSS 0.1%
- Veröffentlicht 01.02.2021 04:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:21
nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID...
CVE-2020-17380
- EPSS 0.3%
- Veröffentlicht 30.01.2021 06:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:58
A heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI device emulation support. It could occur while doing a multi block SDMA transfer via the sdhci_sdma_transfer_multi_blocks() routine in hw/sd/sdhci.c. A guest user or process co...
CVE-2021-3347
- EPSS 0.2%
- Veröffentlicht 29.01.2021 17:15:12
- Zuletzt bearbeitet 25.02.2026 18:16:53
An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.
CVE-2021-3326
- EPSS 0.17%
- Veröffentlicht 27.01.2021 20:15:14
- Zuletzt bearbeitet 09.06.2025 16:15:32
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of ser...
CVE-2021-26117
- EPSS 9.94%
- Veröffentlicht 27.01.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:55:53
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is...