Latest CVE Feed
-
6.1
MEDIUMCVE-2021-20208
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-20206
An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to... Read more
Affected Products : container_network_interface- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20205
Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.... Read more
- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20204
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
3.2
LOWCVE-2021-20203
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash th... Read more
- Published: Feb. 25, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-20202
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The ... Read more
- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20201
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.... Read more
- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-20199
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication.... Read more
Affected Products : podman- Published: Feb. 02, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-20198
A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 1... Read more
Affected Products : openshift_installer- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-20197
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across dif... Read more
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20196
A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to c... Read more
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-20195
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript code being used to process the data. T... Read more
- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20194
There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is reg... Read more
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-20191
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highe... Read more
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-20188
A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-20187
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20186
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20185
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20184
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20183
It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.... Read more
Affected Products : moodle- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024