CVE-2021-32610
- EPSS 2.98%
- Published 30.07.2021 14:15:16
- Last modified 21.11.2024 06:07:22
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
CVE-2021-23414
- EPSS 0.13%
- Published 28.07.2021 08:15:07
- Last modified 21.11.2024 05:51:40
This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.
CVE-2021-37576
- EPSS 0.02%
- Published 26.07.2021 22:15:08
- Last modified 21.11.2024 06:15:27
arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.
CVE-2021-32791
- EPSS 0.51%
- Published 26.07.2021 17:15:08
- Last modified 21.11.2024 06:07:44
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GC...
CVE-2021-32792
- EPSS 0.36%
- Published 26.07.2021 17:15:08
- Last modified 21.11.2024 06:07:45
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is a...
CVE-2021-31292
- EPSS 0.55%
- Published 26.07.2021 17:15:07
- Last modified 21.11.2024 06:05:24
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
CVE-2021-32786
- EPSS 0.16%
- Published 22.07.2021 22:15:08
- Last modified 21.11.2024 06:07:44
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_...
CVE-2021-35063
- EPSS 1.08%
- Published 22.07.2021 18:15:23
- Last modified 21.11.2024 06:11:46
Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."
CVE-2021-37220
- EPSS 0.25%
- Published 21.07.2021 22:15:08
- Last modified 21.11.2024 06:14:53
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
CVE-2021-32761
- EPSS 0.63%
- Published 21.07.2021 21:15:07
- Last modified 21.11.2024 06:07:41
Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5. On 32-bit systems, Redis `*BI...