CVE-2021-31924
- EPSS 0.08%
- Veröffentlicht 26.05.2021 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:31
Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypas...
CVE-2021-33574
- EPSS 0.15%
- Veröffentlicht 25.05.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:09:07
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to...
CVE-2020-25672
- EPSS 2.29%
- Veröffentlicht 25.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:18:25
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
CVE-2020-26555
- EPSS 0.19%
- Veröffentlicht 24.05.2021 18:15:07
- Zuletzt bearbeitet 04.11.2025 20:15:57
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
CVE-2020-26558
- EPSS 0.02%
- Veröffentlicht 24.05.2021 18:15:07
- Zuletzt bearbeitet 04.11.2025 20:15:58
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public ke...
CVE-2021-33477
- EPSS 1.33%
- Veröffentlicht 20.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:08:54
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
CVE-2021-3426
- EPSS 0.09%
- Veröffentlicht 20.05.2021 13:15:07
- Zuletzt bearbeitet 18.12.2025 12:15:54
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other u...
CVE-2021-3480
- EPSS 2.58%
- Veröffentlicht 20.05.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:38
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is ...
CVE-2021-20718
- EPSS 3.06%
- Veröffentlicht 20.05.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 05:47:04
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.
CVE-2021-3421
- EPSS 0.05%
- Veröffentlicht 19.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:27
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from...