CVE-2021-39359
- EPSS 0.16%
- Published 22.08.2021 19:15:07
- Last modified 21.11.2024 06:19:24
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
CVE-2021-39360
- EPSS 0.52%
- Published 22.08.2021 19:15:07
- Last modified 21.11.2024 06:19:24
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
CVE-2021-25218
- EPSS 0.4%
- Published 18.08.2021 19:15:07
- Last modified 21.11.2024 05:54:34
In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the circumstances described above, the named process will terminate due to a failed assertion check. The vu...
CVE-2021-39240
- EPSS 0.07%
- Published 17.08.2021 19:15:08
- Last modified 21.11.2024 06:18:59
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It does not ensure that the scheme and path portions of a URI have the expected characters. For example, the authority field (as observed on a target HTTP/...
CVE-2021-39241
- EPSS 0.44%
- Published 17.08.2021 19:15:08
- Last modified 21.11.2024 06:18:59
An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this ...
CVE-2021-39242
- EPSS 0.47%
- Published 17.08.2021 19:15:08
- Last modified 21.11.2024 06:18:59
An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It can lead to a situation with an attacker-controlled HTTP Host header, because a mismatch between Host and authority is mishandled.
CVE-2021-33193
- EPSS 0.94%
- Published 16.08.2021 08:15:11
- Last modified 01.05.2025 15:40:12
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
CVE-2021-3573
- EPSS 0.02%
- Published 13.08.2021 14:15:07
- Last modified 21.11.2024 06:21:52
A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregister_dev() together with one of the calls hci_sock_bl...
CVE-2021-3635
- EPSS 0.15%
- Published 13.08.2021 14:15:07
- Last modified 21.11.2024 06:22:02
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
CVE-2021-37695
- EPSS 0.4%
- Published 13.08.2021 00:15:07
- Last modified 21.11.2024 06:15:43
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed F...