CVE-2021-31556
- EPSS 0.66%
- Veröffentlicht 12.08.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:05:54
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.
CVE-2021-32808
- EPSS 1.22%
- Veröffentlicht 12.08.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:47
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malform...
CVE-2021-32809
- EPSS 0.21%
- Veröffentlicht 12.08.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:47
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionali...
CVE-2021-38604
- EPSS 0.1%
- Veröffentlicht 12.08.2021 16:15:10
- Zuletzt bearbeitet 30.05.2025 19:15:26
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 ...
CVE-2021-20314
- EPSS 0.17%
- Veröffentlicht 12.08.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:21
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.
CVE-2021-38593
- EPSS 0.69%
- Veröffentlicht 12.08.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:17:36
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
CVE-2021-36770
- EPSS 0.18%
- Veröffentlicht 11.08.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:03
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configura...
CVE-2021-0002
- EPSS 0.07%
- Veröffentlicht 11.08.2021 13:15:15
- Zuletzt bearbeitet 21.11.2024 05:41:40
Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1.4.11 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
CVE-2021-0004
- EPSS 0.14%
- Veröffentlicht 11.08.2021 13:15:15
- Zuletzt bearbeitet 21.11.2024 05:41:40
Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.
CVE-2021-38512
- EPSS 0.42%
- Veröffentlicht 10.08.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:17
An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.