CVE-2021-21333
- EPSS 0.39%
- Veröffentlicht 26.03.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:48:02
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notifications for misse...
- EPSS 0.16%
- Veröffentlicht 26.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:15
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corrupti...
- EPSS 0.42%
- Veröffentlicht 25.03.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 06:21:36
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this v...
CVE-2021-3467
- EPSS 0.07%
- Veröffentlicht 25.03.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 06:21:36
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to cra...
CVE-2021-3443
- EPSS 0.04%
- Veröffentlicht 25.03.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:32
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when open...
CVE-2021-3446
- EPSS 0.04%
- Veröffentlicht 25.03.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:32
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning th...
CVE-2021-3449
- EPSS 10.19%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but incl...
CVE-2021-3450
- EPSS 0.57%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly ...
- EPSS 1.5%
- Veröffentlicht 25.03.2021 10:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:42
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version ...
CVE-2021-3409
- EPSS 0.05%
- Veröffentlicht 23.03.2021 21:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:26
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest ...