CVE-2021-21174
- EPSS 0.59%
- Published 09.03.2021 18:15:16
- Last modified 21.11.2024 05:47:42
Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2021-21175
- EPSS 0.71%
- Published 09.03.2021 18:15:16
- Last modified 21.11.2024 05:47:42
Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2021-21159
- EPSS 1.69%
- Published 09.03.2021 18:15:15
- Last modified 21.11.2024 05:47:40
Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21160
- EPSS 2.31%
- Published 09.03.2021 18:15:15
- Last modified 21.11.2024 05:47:40
Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21161
- EPSS 1.48%
- Published 09.03.2021 18:15:15
- Last modified 21.11.2024 05:47:41
Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21162
- EPSS 1.44%
- Published 09.03.2021 18:15:15
- Last modified 21.11.2024 05:47:41
Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-23351
- EPSS 1.35%
- Published 08.03.2021 05:15:12
- Last modified 21.11.2024 05:51:33
The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Reader wrapping a net.Conn. It will read from the connection until it fi...
CVE-2021-28041
- EPSS 0.26%
- Published 05.03.2021 21:15:13
- Last modified 21.11.2024 05:59:01
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
CVE-2021-3420
- EPSS 0.23%
- Published 05.03.2021 21:15:13
- Last modified 21.11.2024 06:21:27
A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buf...
CVE-2021-3403
- EPSS 0.89%
- Published 04.03.2021 22:15:14
- Last modified 21.11.2024 06:21:25
In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.