CVE-2021-38165
- EPSS 4.28%
- Veröffentlicht 07.08.2021 18:15:06
- Zuletzt bearbeitet 21.11.2024 06:16:32
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
CVE-2021-29923
- EPSS 0.12%
- Veröffentlicht 07.08.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:59
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretati...
CVE-2021-22922
- EPSS 0.18%
- Veröffentlicht 05.08.2021 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:50:55
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, p...
CVE-2021-22923
- EPSS 0.12%
- Veröffentlicht 05.08.2021 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:50:55
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or...
CVE-2021-22924
- EPSS 0.75%
- Veröffentlicht 05.08.2021 21:15:11
- Zuletzt bearbeitet 09.06.2025 15:15:24
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the invo...
CVE-2021-22925
- EPSS 0.42%
- Veröffentlicht 05.08.2021 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:50:55
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be ...
CVE-2021-30578
- EPSS 0.81%
- Veröffentlicht 03.08.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:04:13
Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
CVE-2021-30579
- EPSS 0.81%
- Veröffentlicht 03.08.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:04:13
Use after free in UI framework in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-30580
- EPSS 0.28%
- Veröffentlicht 03.08.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:04:13
Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious application to obtain potentially sensitive information via a crafted HTML page.
CVE-2021-30581
- EPSS 0.26%
- Veröffentlicht 03.08.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:04:13
Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.