CVE-2021-21996
- EPSS 2.74%
- Veröffentlicht 08.09.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:49:24
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
CVE-2021-22004
- EPSS 0.05%
- Veröffentlicht 08.09.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:49:25
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper ...
CVE-2021-28701
- EPSS 0.06%
- Veröffentlicht 08.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:00:10
Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, ar...
CVE-2020-19752
- EPSS 0.33%
- Veröffentlicht 07.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:23
The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
CVE-2021-33287
- EPSS 0.02%
- Veröffentlicht 07.09.2021 15:15:07
- Zuletzt bearbeitet 03.12.2025 15:15:49
In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.
CVE-2021-35266
- EPSS 0.09%
- Veröffentlicht 07.09.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:10
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.
CVE-2021-35267
- EPSS 0.11%
- Veröffentlicht 07.09.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:10
NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.
CVE-2021-39251
- EPSS 0.02%
- Veröffentlicht 07.09.2021 15:15:07
- Zuletzt bearbeitet 02.12.2025 22:16:05
A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.
CVE-2021-39252
- EPSS 0.02%
- Veröffentlicht 07.09.2021 15:15:07
- Zuletzt bearbeitet 02.12.2025 22:16:05
A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.
CVE-2021-39253
- EPSS 0.02%
- Veröffentlicht 07.09.2021 15:15:07
- Zuletzt bearbeitet 02.12.2025 22:16:05
A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.