CVE-2021-3672
- EPSS 0.09%
- Veröffentlicht 23.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:07
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulner...
CVE-2021-44143
- EPSS 7.78%
- Veröffentlicht 22.11.2021 20:15:18
- Zuletzt bearbeitet 21.11.2024 06:30:25
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, ...
CVE-2021-43558
- EPSS 0.45%
- Veröffentlicht 22.11.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:26
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
CVE-2021-43559
- EPSS 0.17%
- Veröffentlicht 22.11.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:26
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
CVE-2021-43560
- EPSS 0.31%
- Veröffentlicht 22.11.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:26
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
CVE-2021-3935
- EPSS 0.14%
- Veröffentlicht 22.11.2021 16:15:07
- Zuletzt bearbeitet 03.11.2025 20:15:50
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBounc...
CVE-2021-28710
- EPSS 0.12%
- Veröffentlicht 21.11.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:11
certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-level translation (EPT), and I...
CVE-2021-21898
- EPSS 0.25%
- Veröffentlicht 19.11.2021 20:15:17
- Zuletzt bearbeitet 21.11.2024 05:49:12
A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigge...
CVE-2021-21899
- EPSS 0.34%
- Veröffentlicht 19.11.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:12
A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigg...
CVE-2021-21900
- EPSS 0.34%
- Veröffentlicht 19.11.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:12
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigge...