Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2021-20319

    An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able... Read more

    Affected Products : coreos-installer
    • Published: Mar. 04, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-20318

    The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.... Read more

    • Published: Dec. 23, 2021
    • Modified: Nov. 21, 2024
  • 4.9

    MEDIUM
    CVE-2021-20317

    A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and ... Read more

    Affected Products : linux_kernel debian_linux
    • Published: Sep. 27, 2021
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2021-20316

    A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.... Read more

    • Published: Aug. 23, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-20315

    A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system... Read more

    Affected Products : gnome-shell stream
    • Published: Feb. 18, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-20314

    Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.... Read more

    Affected Products : enterprise_linux fedora libspf2
    • Published: Aug. 12, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-20313

    A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.... Read more

    Affected Products : debian_linux imagemagick
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-20312

    A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using Image... Read more

    Affected Products : debian_linux imagemagick
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-20311

    A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero in sRGBTransformImage() in the MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker processed by an application... Read more

    Affected Products : imagemagick
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-20310

    A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero ConvertXYZToJzazbz() of MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application us... Read more

    Affected Products : imagemagick
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-20309

    A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an application using ImageMagick. The ... Read more

    Affected Products : debian_linux imagemagick
    • Published: May. 11, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-20308

    Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.... Read more

    Affected Products : debian_linux htmldoc
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2021-20307

    Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.... Read more

    Affected Products : fedora debian_linux libpano13
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-20306

    A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerabi... Read more

    • Published: Jun. 01, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-20305

    A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly r... Read more

    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-20304

    A flaw was found in OpenEXR's hufDecode functionality. This flaw allows an attacker who can pass a crafted file to be processed by OpenEXR, to trigger an undefined right shift error. The highest threat from this vulnerability is to system availability.... Read more

    Affected Products : openexr
    • Published: Aug. 23, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2021-20303

    A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of t... Read more

    Affected Products : debian_linux openexr
    • Published: Mar. 04, 2022
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-20302

    A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is ... Read more

    Affected Products : debian_linux openexr
    • Published: Mar. 04, 2022
    • Modified: Nov. 21, 2024
  • 7.1

    HIGH
    CVE-2021-20300

    A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is ... Read more

    Affected Products : debian_linux openexr
    • Published: Mar. 04, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2021-20299

    A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.... Read more

    Affected Products : debian_linux openexr
    • Published: Mar. 16, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 293646 Results