CVE-2021-21154
- EPSS 1.08%
- Veröffentlicht 22.02.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:40
Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-21155
- EPSS 0.85%
- Veröffentlicht 22.02.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:40
Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-21156
- EPSS 1.6%
- Veröffentlicht 22.02.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:40
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.
CVE-2021-21157
- EPSS 4.74%
- Veröffentlicht 22.02.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:40
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-28463
- EPSS 0.73%
- Veröffentlicht 18.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:22:51
All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Karan Bamal: 1. Download and inst...
CVE-2020-8625
- EPSS 11.06%
- Veröffentlicht 17.02.2021 23:15:13
- Zuletzt bearbeitet 21.11.2024 05:39:09
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by...
CVE-2021-22173
- EPSS 0.5%
- Veröffentlicht 17.02.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:38
Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
CVE-2021-22174
- EPSS 0.19%
- Veröffentlicht 17.02.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:38
Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
CVE-2021-26932
- EPSS 0.19%
- Veröffentlicht 17.02.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:04
An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failure of each one is reported to ...
CVE-2021-26933
- EPSS 0.08%
- Veröffentlicht 17.02.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:04
An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as the ones during scrubbing) have reached the memory ...