CVE-2021-3537
- EPSS 0.11%
- Veröffentlicht 14.05.2021 20:15:16
- Zuletzt bearbeitet 21.11.2024 06:21:47
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could...
CVE-2020-27769
- EPSS 0.08%
- Veröffentlicht 14.05.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:21:48
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
CVE-2021-32613
- EPSS 0.34%
- Veröffentlicht 14.05.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:22
In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
CVE-2021-29510
- EPSS 0.07%
- Veröffentlicht 13.05.2021 19:15:08
- Zuletzt bearbeitet 08.12.2025 16:46:19
Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100...
CVE-2021-29623
- EPSS 0.55%
- Veröffentlicht 13.05.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:31
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ librar...
CVE-2021-32917
- EPSS 2.81%
- Veröffentlicht 13.05.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:55
An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
CVE-2021-32918
- EPSS 2.87%
- Veröffentlicht 13.05.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:55
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
CVE-2021-32919
- EPSS 0.34%
- Veröffentlicht 13.05.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:55
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, al...
CVE-2021-32920
- EPSS 3.29%
- Veröffentlicht 13.05.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:55
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
CVE-2021-32921
- EPSS 3.8%
- Veröffentlicht 13.05.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:55
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret str...