CVE-2019-25051
- EPSS 0.03%
- Veröffentlicht 20.07.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:50
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
CVE-2020-36430
- EPSS 0.38%
- Veröffentlicht 20.07.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 05:29:29
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
CVE-2021-36976
- EPSS 0.11%
- Veröffentlicht 20.07.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:25
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
CVE-2021-32760
- EPSS 0.07%
- Veröffentlicht 19.07.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:41
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem...
CVE-2021-32749
- EPSS 0.3%
- Veröffentlicht 16.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:39
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action ma...
CVE-2021-34558
- EPSS 1.48%
- Veröffentlicht 15.07.2021 14:15:19
- Zuletzt bearbeitet 21.11.2024 06:10:40
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
CVE-2021-36740
- EPSS 0.12%
- Veröffentlicht 14.07.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:59
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x be...
CVE-2021-24119
- EPSS 0.26%
- Veröffentlicht 14.07.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:23
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software runni...
CVE-2021-34552
- EPSS 0.34%
- Veröffentlicht 13.07.2021 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:10:39
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
CVE-2021-32703
- EPSS 0.56%
- Veröffentlicht 12.07.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:33
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share to...