CVE-2021-29458
- EPSS 0.1%
- Veröffentlicht 19.04.2021 19:15:18
- Zuletzt bearbeitet 21.11.2024 06:01:08
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used t...
CVE-2021-29457
- EPSS 1.51%
- Veröffentlicht 19.04.2021 19:15:17
- Zuletzt bearbeitet 21.11.2024 06:01:08
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to wr...
CVE-2021-20288
- EPSS 0.18%
- Veröffentlicht 15.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:17
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of ...
CVE-2021-28484
- EPSS 0.56%
- Veröffentlicht 14.04.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:59:45
An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of the request, which can lead to a state where yubihsm-connector becomes...
CVE-2021-29338
- EPSS 0.11%
- Veröffentlicht 14.04.2021 14:15:14
- Zuletzt bearbeitet 03.11.2025 20:15:46
Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.
CVE-2021-27815
- EPSS 0.22%
- Veröffentlicht 14.04.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:58:36
NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.
CVE-2021-22879
- EPSS 2.28%
- Veröffentlicht 14.04.2021 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:50:49
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
CVE-2020-36323
- EPSS 0.71%
- Veröffentlicht 14.04.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:16
In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes after its length is checked.
CVE-2021-31162
- EPSS 1.89%
- Veröffentlicht 14.04.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 06:05:12
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.
CVE-2021-21392
- EPSS 0.2%
- Veröffentlicht 12.04.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:48:15
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains were not restricted to ...