CVE-2021-21108
- EPSS 1.31%
- Published 08.01.2021 19:15:14
- Last modified 21.11.2024 05:47:35
Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2020-25678
- EPSS 0.02%
- Published 08.01.2021 18:15:13
- Last modified 21.11.2024 05:18:26
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
CVE-2020-8265
- EPSS 0.8%
- Published 06.01.2021 21:15:14
- Last modified 21.11.2024 05:38:37
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap ...
CVE-2020-8287
- EPSS 11.16%
- Published 06.01.2021 21:15:14
- Last modified 21.11.2024 05:38:39
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This c...
CVE-2020-27842
- EPSS 0.07%
- Published 05.01.2021 18:15:14
- Last modified 21.11.2024 05:21:54
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.
CVE-2020-27843
- EPSS 0.08%
- Published 05.01.2021 18:15:14
- Last modified 21.11.2024 05:21:55
A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system ...
CVE-2020-27845
- EPSS 0.07%
- Published 05.01.2021 18:15:14
- Last modified 21.11.2024 05:21:55
There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw ...
CVE-2020-27841
- EPSS 0.08%
- Published 05.01.2021 18:15:13
- Last modified 21.11.2024 05:21:54
There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to...
CVE-2020-36158
- EPSS 0.63%
- Published 05.01.2021 05:15:10
- Last modified 21.11.2024 05:28:50
mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.
CVE-2019-25013
- EPSS 0.68%
- Published 04.01.2021 18:15:13
- Last modified 09.06.2025 16:15:30
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.