CVE-2020-36277
- EPSS 6.65%
- Published 11.03.2021 21:15:11
- Last modified 21.11.2024 05:29:11
Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
CVE-2021-21381
- EPSS 0.12%
- Published 11.03.2021 17:15:12
- Last modified 21.11.2024 05:48:14
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to ga...
CVE-2021-27919
- EPSS 0.13%
- Published 11.03.2021 00:15:12
- Last modified 21.11.2024 05:58:48
archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.
CVE-2021-21334
- EPSS 0.36%
- Published 10.03.2021 22:15:12
- Last modified 21.11.2024 05:48:02
In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) ...
CVE-2021-20205
- EPSS 0.44%
- Published 10.03.2021 17:15:15
- Last modified 21.11.2024 05:46:07
Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.
CVE-2021-21772
- EPSS 3.75%
- Published 10.03.2021 17:15:15
- Last modified 21.11.2024 05:48:56
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerab...
CVE-2021-28116
- EPSS 10.52%
- Published 09.03.2021 22:15:12
- Last modified 21.11.2024 05:59:06
Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
CVE-2020-35524
- EPSS 0.37%
- Published 09.03.2021 20:15:13
- Last modified 21.11.2024 05:27:29
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, in...
CVE-2021-21300
- EPSS 74.69%
- Published 09.03.2021 20:15:13
- Last modified 21.11.2024 05:47:58
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be e...
CVE-2020-35521
- EPSS 0.08%
- Published 09.03.2021 20:15:12
- Last modified 21.11.2024 05:27:29
A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.