CVE-2021-45931
- EPSS 0.77%
 - Published 01.01.2022 01:15:08
 - Last modified 21.11.2024 06:33:17
 
HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).
CVE-2021-45958
- EPSS 0.29%
 - Published 01.01.2022 00:15:08
 - Last modified 21.11.2024 06:33:22
 
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
CVE-2021-4193
- EPSS 0.27%
 - Published 31.12.2021 16:15:07
 - Last modified 21.11.2024 06:37:07
 
vim is vulnerable to Out-of-bounds Read
CVE-2021-4192
- EPSS 0.27%
 - Published 31.12.2021 15:15:08
 - Last modified 21.11.2024 06:37:06
 
vim is vulnerable to Use After Free
CVE-2021-4181
- EPSS 0.27%
 - Published 30.12.2021 22:15:10
 - Last modified 03.11.2025 22:15:53
 
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
CVE-2021-4182
- EPSS 0.05%
 - Published 30.12.2021 22:15:10
 - Last modified 03.11.2025 22:15:53
 
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
CVE-2021-4183
- EPSS 0.18%
 - Published 30.12.2021 22:15:10
 - Last modified 21.11.2024 06:37:05
 
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
CVE-2021-4184
- EPSS 0.22%
 - Published 30.12.2021 22:15:10
 - Last modified 03.11.2025 22:15:53
 
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
CVE-2021-4185
- EPSS 0.22%
 - Published 30.12.2021 22:15:10
 - Last modified 03.11.2025 22:15:53
 
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
CVE-2021-4186
- EPSS 0.08%
 - Published 30.12.2021 22:15:10
 - Last modified 03.11.2025 22:15:53
 
Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file