Latest CVE Feed
-
6.8
MEDIUMCVE-2021-20328
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM a... Read more
- Published: Feb. 25, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-20327
A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of... Read more
Affected Products : libmongocrypt- Published: Feb. 25, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20326
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.4.... Read more
Affected Products : mongodb- Published: Apr. 30, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-20325
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Re... Read more
Affected Products : enterprise_linux- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20323
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.... Read more
Affected Products : keycloak- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-20322
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the s... Read more
Affected Products : linux_kernel fedora debian_linux active_iq_unified_manager solidfire_\&_hci_management_node e-series_santricity_os_controller h300s_firmware h500s_firmware h700s_firmware h410s_firmware +22 more products- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2021-20321
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to crash the system.... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-20320
A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20319
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able... Read more
Affected Products : coreos-installer- Published: Mar. 04, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-20318
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.... Read more
Affected Products : jboss_enterprise_application_platform- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-20317
A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and ... Read more
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-20316
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.... Read more
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20315
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20314
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.... Read more
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20313
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.... Read more
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20312
A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using Image... Read more
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20311
A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero in sRGBTransformImage() in the MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker processed by an application... Read more
Affected Products : imagemagick- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20310
A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero ConvertXYZToJzazbz() of MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application us... Read more
Affected Products : imagemagick- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20309
A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an application using ImageMagick. The ... Read more
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20308
Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.... Read more
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024