Количество 25 356
Количество 25 356
CVE-2021-46663
MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
CVE-2021-46662
MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.
CVE-2021-46661
MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).
CVE-2021-46659
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
CVE-2021-46658
save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.
CVE-2021-46657
get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
CVE-2021-46283
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace.
CVE-2021-46143
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3 an integer overflow exists for m_groupSize.
CVE-2021-46023
An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation fault and application crash.
CVE-2021-45985
Mitre: CVE-2021-45985 Erroneous finalizer call in Lua leads to a heap-based buffer over-read
CVE-2021-45960
In Expat (aka libexpat) before 2.4.3 a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g. allocating too few bytes or only freeing memory).
CVE-2021-45957
CVE-2021-45956
CVE-2021-45955
CVE-2021-45954
CVE-2021-45953
CVE-2021-45952
CVE-2021-45868
In the Linux kernel before 5.15.3 fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can for example lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file.
CVE-2021-45707
CVE-2021-45486
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-46663 MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-46662 MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-46661 MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE). | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-46659 MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
CVE-2021-46658 save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-46657 get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-46283 nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_elem_expr_alloc. A local user can set a netfilter table expression in their own namespace. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2021-46143 In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3 an integer overflow exists for m_groupSize. | CVSS3: 7.8 | 4% Низкий | больше 4 лет назад | |
CVE-2021-46023 An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation fault and application crash. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2021-45985 Mitre: CVE-2021-45985 Erroneous finalizer call in Lua leads to a heap-based buffer over-read | CVSS3: 5.5 | 1% Низкий | больше 1 года назад | |
CVE-2021-45960 In Expat (aka libexpat) before 2.4.3 a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g. allocating too few bytes or only freeing memory). | CVSS3: 8.8 | 4% Низкий | больше 4 лет назад | |
CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | ||
CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | ||
CVE-2021-45868 In the Linux kernel before 5.15.3 fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can for example lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
CVSS3: 9.8 | 2% Низкий | почти 2 года назад | ||
CVSS3: 3.5 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу