CVE-2021-21274
- EPSS 0.58%
- Veröffentlicht 26.02.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:54
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their ...
CVE-2020-24455
- EPSS 0.1%
- Veröffentlicht 26.02.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:51
Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.
CVE-2021-21330
- EPSS 0.49%
- Veröffentlicht 26.02.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:48:02
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a differe...
CVE-2021-26701
- EPSS 1.9%
- Veröffentlicht 25.02.2021 23:15:16
- Zuletzt bearbeitet 21.11.2024 05:56:41
.NET Core Remote Code Execution Vulnerability
CVE-2021-20203
- EPSS 0.03%
- Veröffentlicht 25.02.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:46:07
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to cra...
CVE-2021-3406
- EPSS 0.1%
- Veröffentlicht 25.02.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:21:25
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
CVE-2020-11987
- EPSS 1.36%
- Veröffentlicht 24.02.2021 18:15:11
- Zuletzt bearbeitet 03.11.2025 20:15:42
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arb...
CVE-2020-11988
- EPSS 0.18%
- Veröffentlicht 24.02.2021 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:03
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying...
CVE-2020-28599
- EPSS 1.36%
- Veröffentlicht 24.02.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:22:59
A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can provide a malicious file to trigger this vul...
CVE-2021-27645
- EPSS 0.04%
- Veröffentlicht 24.02.2021 15:15:13
- Zuletzt bearbeitet 09.06.2025 15:15:25
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the loc...