Latest CVE Feed
-
7.8
HIGHCVE-2021-3496
A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.... Read more
Affected Products : jhead- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-3495
An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability and deploy a given... Read more
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-3494
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated atta... Read more
Affected Products : foreman- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-3492
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker cou... Read more
- Published: Apr. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-3491
The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used to create a heap overflow leading ... Read more
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3490
The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue w... Read more
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3489
The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. Th... Read more
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-3486
GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.... Read more
Affected Products : glpi- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2021-3485
An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This i... Read more
Affected Products : endpoint_security_tools- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3483
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confiden... Read more
Affected Products : linux_kernel debian_linux h410c_firmware cloud_backup h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s +9 more products- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3482
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious... Read more
- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-3481
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an una... Read more
Affected Products : qt- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3480
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to sy... Read more
- Published: May. 20, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-3479
There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption of memory, resulting in an impact to system availability.... Read more
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-3478
There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system availabi... Read more
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-3477
There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, subsequently leading to an out-of-bounds read. The... Read more
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-3476
A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.... Read more
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-3475
There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.... Read more
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-3474
There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.... Read more
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-3473
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore... Read more
Affected Products : xclarity_controller thinksystem_sr630 thinksystem_sd530 thinksystem_sd650 thinksystem_sn550 thinksystem_sn850 thinksystem_sr150 thinksystem_sr158 thinksystem_sr250 thinksystem_sr258 +28 more products- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024