Latest CVE Feed
-
7.8
HIGHCVE-2021-38258
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().... Read more
Affected Products : mcuxpresso_software_development_kit- EPSS Score: %0.06
- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38244
A regular expression denial of service (ReDoS) vulnerability exits in cbioportal 3.6.21 and older via a POST request to /ProteinArraySignificanceTest.json.... Read more
Affected Products : cbioportal- EPSS Score: %0.28
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38221
bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.... Read more
Affected Products : bbs-go- EPSS Score: %0.18
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-38209
net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL_CT_EXPECT_MAX, ... Read more
Affected Products : linux_kernel- EPSS Score: %0.09
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38208
net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NULL pointer dereference and BUG) by making a getsockname call after a certain type of failure of a bind call.... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38207
drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.... Read more
Affected Products : linux_kernel- EPSS Score: %2.48
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38206
The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers to cause a denial of service (NULL pointer dereference in the radiotap parser) by injecting a frame with 802.11a rates.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-38205
drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).... Read more
- EPSS Score: %0.07
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-38204
drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.... Read more
- EPSS Score: %0.06
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38203
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.... Read more
Affected Products : linux_kernel hci_management_node solidfire element_software hci_storage_node hci_bootstrap_os hci_compute_node- EPSS Score: %0.05
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38202
fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd.... Read more
Affected Products : linux_kernel hci_management_node solidfire element_software hci_storage_node hci_bootstrap_os hci_compute_node- EPSS Score: %1.45
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38201
net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.... Read more
Affected Products : linux_kernel hci_management_node solidfire element_software hci_storage_node hci_bootstrap_os hci_compute_node- EPSS Score: %0.52
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38200
arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13, on systems with perf_event_paranoid=-1 and no specific PMU driver support registered, allows local users to cause a denial of service (perf_instruction_pointer NULL pointer dereference an... Read more
Affected Products : linux_kernel- EPSS Score: %0.04
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-38199
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking... Read more
- EPSS Score: %0.28
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38198
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.... Read more
- EPSS Score: %0.08
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-38197
unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR archive.... Read more
Affected Products : go-unarr- EPSS Score: %0.87
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38196
An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitrary code via proc-macros, and otherwise has no legitimate purpose.... Read more
Affected Products : better-macro- EPSS Score: %3.36
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38195
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow.... Read more
Affected Products : libsecp256k1- EPSS Score: %0.17
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38194
An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the FieldVar::mul_by_inverse method. Thus, a prover can produce a proof that is unsound but is nonetheless verified.... Read more
Affected Products : ark-r1cs-std- EPSS Score: %0.36
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38193
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.... Read more
Affected Products : ammonia- EPSS Score: %0.20
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024