CVE-2021-42715
- EPSS 0.14%
- Veröffentlicht 21.10.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:01
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb...
CVE-2021-42716
- EPSS 0.19%
- Veröffentlicht 21.10.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:01
An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potenti...
CVE-2021-41159
- EPSS 0.07%
- Veröffentlicht 21.10.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:37
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (`/gt:rpc`) fail to validate input data. A malicious gateway might allow cl...
CVE-2021-41160
- EPSS 0.13%
- Veröffentlicht 21.10.2021 19:15:07
- Zuletzt bearbeitet 03.11.2025 21:15:42
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to sen...
CVE-2021-42327
- EPSS 0.25%
- Veröffentlicht 21.10.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:36
dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There a...
CVE-2021-42762
- EPSS 0.01%
- Veröffentlicht 20.10.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:07
BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that ...
CVE-2021-35610
- EPSS 0.75%
- Veröffentlicht 20.10.2021 11:17:08
- Zuletzt bearbeitet 21.11.2024 06:12:38
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple prot...
CVE-2021-35608
- EPSS 0.21%
- Veröffentlicht 20.10.2021 11:17:07
- Zuletzt bearbeitet 21.11.2024 06:12:38
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access ...
CVE-2021-35604
- EPSS 0.21%
- Veröffentlicht 20.10.2021 11:17:06
- Zuletzt bearbeitet 21.11.2024 06:12:37
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via mu...
- EPSS 0.3%
- Veröffentlicht 20.10.2021 11:17:06
- Zuletzt bearbeitet 21.11.2024 06:12:38
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols ...