Количество 25 356
Количество 25 356
CVE-2021-39922
CVE-2021-39921
CVE-2021-39920
CVE-2021-3984
Heap-based Buffer Overflow in vim/vim
CVE-2021-3981
A flaw in grub2 was found where its configuration file known as grub.cfg is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.
CVE-2021-3975
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
CVE-2021-3974
Use After Free in vim/vim
CVE-2021-3973
Heap-based Buffer Overflow in vim/vim
CVE-2021-3968
Heap-based Buffer Overflow in vim/vim
CVE-2021-39537
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
CVE-2021-3947
CVE-2021-3935
When PgBouncer is configured to use "cert" authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
CVE-2021-3930
CVE-2021-3929
CVE-2021-3928
Use of Uninitialized Variable in vim/vim
CVE-2021-3927
Heap-based Buffer Overflow in vim/vim
CVE-2021-39275
ap_escape_quotes buffer overflow
CVE-2021-39272
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances such as a certain situation with IMAP and PREAUTH.
CVE-2021-39263
A crafted NTFS image can trigger a heap-based buffer overflow caused by an unsanitized attribute in ntfs_get_attribute_value in NTFS-3G < 2021.8.22.
CVE-2021-39262
A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 7.5 | 5% Низкий | больше 4 лет назад | ||
CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | ||
CVE-2021-3984 Heap-based Buffer Overflow in vim/vim | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-3981 A flaw in grub2 was found where its configuration file known as grub.cfg is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released. | CVSS3: 3.3 | 0% Низкий | 6 месяцев назад | |
CVE-2021-3975 A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
CVE-2021-3974 Use After Free in vim/vim | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
CVE-2021-3973 Heap-based Buffer Overflow in vim/vim | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
CVE-2021-3968 Heap-based Buffer Overflow in vim/vim | CVSS3: 8 | 2% Низкий | больше 4 лет назад | |
CVE-2021-39537 An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow. | CVSS3: 8.8 | 3% Низкий | почти 5 лет назад | |
CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | ||
CVE-2021-3935 When PgBouncer is configured to use "cert" authentication a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1. | CVSS3: 8.1 | 1% Низкий | больше 4 лет назад | |
CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | ||
CVSS3: 8.2 | 1% Низкий | почти 2 года назад | ||
CVE-2021-3928 Use of Uninitialized Variable in vim/vim | CVSS3: 7.8 | 1% Низкий | почти 5 лет назад | |
CVE-2021-3927 Heap-based Buffer Overflow in vim/vim | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
CVE-2021-39275 ap_escape_quotes buffer overflow | CVSS3: 9.8 | 39% Средний | почти 5 лет назад | |
CVE-2021-39272 Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances such as a certain situation with IMAP and PREAUTH. | CVSS3: 5.9 | 1% Низкий | больше 4 лет назад | |
CVE-2021-39263 A crafted NTFS image can trigger a heap-based buffer overflow caused by an unsanitized attribute in ntfs_get_attribute_value in NTFS-3G < 2021.8.22. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
CVE-2021-39262 A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу