CVE-2021-32749
- EPSS 0.3%
- Veröffentlicht 16.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:39
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action ma...
CVE-2021-34558
- EPSS 1.48%
- Veröffentlicht 15.07.2021 14:15:19
- Zuletzt bearbeitet 21.11.2024 06:10:40
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
CVE-2021-36740
- EPSS 0.71%
- Veröffentlicht 14.07.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:59
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x be...
CVE-2021-24119
- EPSS 0.34%
- Veröffentlicht 14.07.2021 13:15:08
- Zuletzt bearbeitet 03.11.2025 20:15:45
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software runni...
CVE-2021-34552
- EPSS 0.34%
- Veröffentlicht 13.07.2021 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:10:39
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
CVE-2021-32703
- EPSS 0.56%
- Veröffentlicht 12.07.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:33
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share to...
CVE-2021-32705
- EPSS 0.57%
- Veröffentlicht 12.07.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:34
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share t...
CVE-2021-32680
- EPSS 0.2%
- Veröffentlicht 12.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:31
Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event...
CVE-2021-32688
- EPSS 2.35%
- Veröffentlicht 12.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:32
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can ...
CVE-2021-32679
- EPSS 0.95%
- Veröffentlicht 12.07.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:30
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized...