CVE-2021-30574
- EPSS 0.81%
- Veröffentlicht 03.08.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:12
Use after free in protocol handling in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30575
- EPSS 0.81%
- Veröffentlicht 03.08.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:12
Out of bounds write in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30576
- EPSS 0.26%
- Veröffentlicht 03.08.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:12
Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30577
- EPSS 0.39%
- Veröffentlicht 03.08.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:13
Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.
CVE-2021-3673
- EPSS 0.65%
- Veröffentlicht 02.08.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 06:22:07
A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS.
CVE-2021-32810
- EPSS 1.08%
- Veröffentlicht 02.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:47
crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in the worker queue can be popped twice inste...
CVE-2021-34556
- EPSS 0.04%
- Veröffentlicht 02.08.2021 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:10:40
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory l...
CVE-2021-35477
- EPSS 0.04%
- Veröffentlicht 02.08.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:21
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a st...
CVE-2021-37746
- EPSS 0.48%
- Veröffentlicht 30.07.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:15:51
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
CVE-2021-36386
- EPSS 0.26%
- Veröffentlicht 30.07.2021 14:15:18
- Zuletzt bearbeitet 21.11.2024 06:13:39
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE...