CVE-2021-39226
- EPSS 94.35%
- Published 05.10.2021 18:15:07
- Last modified 24.10.2025 14:47:23
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots...
CVE-2021-41524
- EPSS 7.1%
- Published 05.10.2021 09:15:07
- Last modified 21.11.2024 06:26:20
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in versi...
CVE-2021-41773
- EPSS 94.38%
- Published 05.10.2021 09:15:07
- Last modified 27.10.2025 17:36:57
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directorie...
CVE-2021-41089
- EPSS 0.03%
- Published 04.10.2021 21:15:12
- Last modified 21.11.2024 06:25:26
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permission chang...
CVE-2021-41091
- EPSS 4.88%
- Published 04.10.2021 21:15:12
- Last modified 21.11.2024 06:25:26
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, ...
CVE-2021-41092
- EPSS 0.08%
- Published 04.10.2021 20:15:07
- Last modified 21.11.2024 06:25:26
Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configuration file (typically `~/.docker/config.json`) list...
- EPSS 0.87%
- Published 04.10.2021 18:15:09
- Last modified 21.11.2024 06:07:41
Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a result of a...
CVE-2021-41099
- EPSS 0.37%
- Published 04.10.2021 18:15:09
- Last modified 21.11.2024 06:25:27
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code execution. The vulnerability invo...
CVE-2021-32626
- EPSS 1.17%
- Published 04.10.2021 18:15:08
- Last modified 21.11.2024 06:07:24
Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result...
CVE-2021-32627
- EPSS 0.8%
- Published 04.10.2021 18:15:08
- Last modified 21.11.2024 06:07:24
Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves changing the d...