CVE-2021-28965
- EPSS 0.36%
- Veröffentlicht 21.04.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 06:00:27
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.
CVE-2021-29155
- EPSS 0.21%
- Veröffentlicht 20.04.2021 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:00:47
An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information f...
CVE-2021-20208
- EPSS 0.34%
- Veröffentlicht 19.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:07
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity...
CVE-2021-3505
- EPSS 0.13%
- Veröffentlicht 19.04.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:42
A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called...
CVE-2021-29458
- EPSS 0.1%
- Veröffentlicht 19.04.2021 19:15:18
- Zuletzt bearbeitet 21.11.2024 06:01:08
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used t...
CVE-2021-29457
- EPSS 1.51%
- Veröffentlicht 19.04.2021 19:15:17
- Zuletzt bearbeitet 21.11.2024 06:01:08
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to wr...
CVE-2021-20288
- EPSS 0.18%
- Veröffentlicht 15.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:17
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of ...
CVE-2021-28484
- EPSS 0.56%
- Veröffentlicht 14.04.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:59:45
An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of the request, which can lead to a state where yubihsm-connector becomes...
CVE-2021-29338
- EPSS 0.1%
- Veröffentlicht 14.04.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 06:00:58
Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.
CVE-2021-27815
- EPSS 0.32%
- Veröffentlicht 14.04.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:58:36
NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.