CVE-2021-21261
- EPSS 0.21%
- Veröffentlicht 14.01.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:53
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox es...
CVE-2021-23926
- EPSS 0.44%
- Veröffentlicht 14.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:03
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
CVE-2021-24122
- EPSS 61%
- Veröffentlicht 14.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:23
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. ...
CVE-2020-16119
- EPSS 0.09%
- Veröffentlicht 14.01.2021 01:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:47
Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-...
CVE-2020-28374
- EPSS 0.31%
- Veröffentlicht 13.01.2021 04:15:12
- Zuletzt bearbeitet 21.11.2024 05:22:41
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c938...
CVE-2020-35459
- EPSS 0.05%
- Veröffentlicht 12.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:19
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privi...
CVE-2021-23239
- EPSS 0.1%
- Veröffentlicht 12.01.2021 09:15:14
- Zuletzt bearbeitet 21.11.2024 05:51:25
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
CVE-2020-35653
- EPSS 0.29%
- Veröffentlicht 12.01.2021 09:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:46
In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.
CVE-2021-0308
- EPSS 0.08%
- Veröffentlicht 11.01.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:42:28
In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVE-2020-26298
- EPSS 1.13%
- Veröffentlicht 11.01.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:19:47
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quot...