Количество 25 356
Количество 25 356
CVE-2021-43882
Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-43880
Windows Mobile Device Management Elevation of Privilege Vulnerability
CVE-2021-43877
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
CVE-2021-43876
Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2021-43875
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2021-43818
HTML Cleaner allows crafted and SVG embedded scripts to pass through
CVE-2021-43784
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration
CVE-2021-43767
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.
CVE-2021-43766
Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of SSL certificate verification and encryption. This is similar to CVE-2021-23214 for PostgreSQL.
CVE-2021-43666
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
CVE-2021-43618
GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input leading to a segmentation fault on 32-bit platforms.
CVE-2021-43566
CVE-2021-43565
CVE-2021-43527
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS S/MIME PKCS \#7 or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS X.509 OCSP or CRL functionality may be impacted depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However email clients and PDF viewers that use NSS for signature verification such as Thunderbird LibreOffice Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.
CVE-2021-43523
In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters in domain names returned by DNS servers via gethostbyname getaddrinfo gethostbyaddr and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution XSS applications crashes etc.). In other words a validation step which is expected in any stub resolver does not occur.
CVE-2021-43519
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
CVE-2021-43396
In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34 remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be invoked through user input and requires iconv to be invoked with a NULL inbuf which ought to require a separate application bug to do so unintentionally. Hence there's no security impact to the bug.
CVE-2021-43389
An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.
CVE-2021-43267
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
CVE-2021-43256
Microsoft Excel Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-43882 Microsoft Defender for IoT Remote Code Execution Vulnerability | CVSS3: 9 | 2% Низкий | больше 4 лет назад | |
CVE-2021-43880 Windows Mobile Device Management Elevation of Privilege Vulnerability | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
CVE-2021-43877 ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-43876 Microsoft SharePoint Elevation of Privilege Vulnerability | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
CVE-2021-43875 Microsoft Office Graphics Remote Code Execution Vulnerability | CVSS3: 7.8 | 5% Низкий | больше 4 лет назад | |
CVE-2021-43818 HTML Cleaner allows crafted and SVG embedded scripts to pass through | CVSS3: 7.1 | 2% Низкий | больше 4 лет назад | |
CVE-2021-43784 Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration | CVSS3: 5 | 2% Низкий | больше 4 лет назад | |
CVE-2021-43767 Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL. | CVSS3: 5.9 | 0% Низкий | почти 4 года назад | |
CVE-2021-43766 Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of SSL certificate verification and encryption. This is similar to CVE-2021-23214 for PostgreSQL. | CVSS3: 8.1 | 0% Низкий | почти 4 года назад | |
CVE-2021-43666 A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0. | 2% Низкий | 11 месяцев назад | ||
CVE-2021-43618 GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input leading to a segmentation fault on 32-bit platforms. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
CVSS3: 2.5 | 0% Низкий | почти 2 года назад | ||
CVSS3: 7.5 | 1% Низкий | больше 1 года назад | ||
CVE-2021-43527 NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS S/MIME PKCS \#7 or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS X.509 OCSP or CRL functionality may be impacted depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However email clients and PDF viewers that use NSS for signature verification such as Thunderbird LibreOffice Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1. | CVSS3: 9.8 | 18% Средний | больше 4 лет назад | |
CVE-2021-43523 In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters in domain names returned by DNS servers via gethostbyname getaddrinfo gethostbyaddr and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution XSS applications crashes etc.). In other words a validation step which is expected in any stub resolver does not occur. | CVSS3: 9.6 | 3% Низкий | больше 4 лет назад | |
CVE-2021-43519 Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
CVE-2021-43396 In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34 remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be invoked through user input and requires iconv to be invoked with a NULL inbuf which ought to require a separate application bug to do so unintentionally. Hence there's no security impact to the bug. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
CVE-2021-43389 An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. | CVSS3: 5.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-43267 An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type. | CVSS3: 9.8 | 58% Средний | почти 5 лет назад | |
CVE-2021-43256 Microsoft Excel Remote Code Execution Vulnerability | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу