CVE-2021-40401
- EPSS 0.28%
- Veröffentlicht 04.02.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 06:24:03
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a...
CVE-2021-40403
- EPSS 0.13%
- Veröffentlicht 04.02.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 06:24:03
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a ...
CVE-2022-22818
- EPSS 1.2%
- Veröffentlicht 03.02.2022 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:47:30
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
CVE-2022-23833
- EPSS 3.67%
- Veröffentlicht 03.02.2022 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:49:20
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
CVE-2022-0443
- EPSS 0.18%
- Veröffentlicht 02.02.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:38:38
Use After Free in GitHub repository vim/vim prior to 8.2.
CVE-2022-21724
- EPSS 4.81%
- Veröffentlicht 02.02.2022 12:15:08
- Zuletzt bearbeitet 05.05.2025 17:17:48
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or propertie...
CVE-2022-0417
- EPSS 0.34%
- Veröffentlicht 01.02.2022 13:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:49
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
CVE-2021-43859
- EPSS 1.94%
- Veröffentlicht 01.02.2022 12:15:08
- Zuletzt bearbeitet 03.11.2025 22:15:52
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resul...
CVE-2022-0419
- EPSS 0.25%
- Veröffentlicht 01.02.2022 11:15:11
- Zuletzt bearbeitet 21.11.2024 06:38:35
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
CVE-2021-46667
- EPSS 0.04%
- Veröffentlicht 01.02.2022 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:34:33
MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.