CVE-2021-30574
- EPSS 0.81%
- Published 03.08.2021 20:15:08
- Last modified 21.11.2024 06:04:12
Use after free in protocol handling in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30575
- EPSS 0.81%
- Published 03.08.2021 20:15:08
- Last modified 21.11.2024 06:04:12
Out of bounds write in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30576
- EPSS 0.26%
- Published 03.08.2021 20:15:08
- Last modified 21.11.2024 06:04:12
Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30577
- EPSS 0.39%
- Published 03.08.2021 20:15:08
- Last modified 21.11.2024 06:04:13
Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.
CVE-2021-3673
- EPSS 0.65%
- Published 02.08.2021 19:15:13
- Last modified 21.11.2024 06:22:07
A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS.
CVE-2021-32810
- EPSS 1.08%
- Published 02.08.2021 19:15:08
- Last modified 21.11.2024 06:07:47
crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in the worker queue can be popped twice inste...
CVE-2021-34556
- EPSS 0.04%
- Published 02.08.2021 05:15:07
- Last modified 21.11.2024 06:10:40
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory l...
CVE-2021-35477
- EPSS 0.04%
- Published 02.08.2021 04:15:07
- Last modified 21.11.2024 06:12:21
In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a st...
CVE-2021-37746
- EPSS 0.48%
- Published 30.07.2021 15:15:09
- Last modified 21.11.2024 06:15:51
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
CVE-2021-36386
- EPSS 0.26%
- Published 30.07.2021 14:15:18
- Last modified 21.11.2024 06:13:39
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE...