Latest CVE Feed
-
5.8
MEDIUMCVE-2021-3504
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory bey... Read more
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-3503
A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerability is to the confidentiality.... Read more
Affected Products : wildfly- Published: Apr. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-3502
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hos... Read more
Affected Products : avahi- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-3501
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from t... Read more
Affected Products : linux_kernel enterprise_linux fedora solidfire_baseboard_management_controller_firmware h410c_firmware cloud_backup h300s_firmware h500s_firmware h700s_firmware h410s_firmware +17 more products- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3500
A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences.... Read more
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-3499
A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules when there is multiple DNS rules. It could lead to potentially lose of confidentiality, integrity or availab... Read more
Affected Products : ovn-kubernetes- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3498
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3497
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3496
A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.... Read more
Affected Products : jhead- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-3495
An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability and deploy a given... Read more
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-3494
A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated atta... Read more
Affected Products : foreman- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-3492
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker cou... Read more
- Published: Apr. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-3491
The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used to create a heap overflow leading ... Read more
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3490
The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue w... Read more
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3489
The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. Th... Read more
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-3486
GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.... Read more
Affected Products : glpi- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2021-3485
An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This i... Read more
Affected Products : endpoint_security_tools- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3483
A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-linked list, leading to a use-after-free when one of these devices is removed. The highest threat from this vulnerability is to confiden... Read more
Affected Products : linux_kernel debian_linux h410c_firmware cloud_backup h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s +9 more products- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3482
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious... Read more
- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-3481
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an una... Read more
Affected Products : qt- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024