CVE-2020-36327
- EPSS 15.57%
- Veröffentlicht 29.04.2021 03:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:17
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem t...
CVE-2021-25215
- EPSS 2.52%
- Veröffentlicht 29.04.2021 01:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:33
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable ...
CVE-2021-25214
- EPSS 1.01%
- Veröffentlicht 29.04.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 05:54:33
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, ...
CVE-2021-29472
- EPSS 3.59%
- Veröffentlicht 27.04.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:11
Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed in the HgDriver if hg/Mercuria...
CVE-2021-29473
- EPSS 0.14%
- Veröffentlicht 26.04.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:11
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for rea...
CVE-2021-21201
- EPSS 0.91%
- Veröffentlicht 26.04.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:45
Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-21202
- EPSS 0.2%
- Veröffentlicht 26.04.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:46
Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVE-2021-21203
- EPSS 1.39%
- Veröffentlicht 26.04.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:46
Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21204
- EPSS 1.4%
- Veröffentlicht 26.04.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:46
Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21205
- EPSS 0.44%
- Veröffentlicht 26.04.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:46
Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.