Количество 25 355
Количество 25 355
CVE-2021-3468
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service which becomes unresponsive after this flaw is triggered.
CVE-2021-3467
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
CVE-2021-34558
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange allowing a malicious TLS server to cause a TLS client to panic.
CVE-2021-34556
In the Linux kernel through 5.13.7 an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.
CVE-2021-34537
Windows Bluetooth Driver Elevation of Privilege Vulnerability
CVE-2021-34536
Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2021-34535
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-34534
Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2021-34533
Windows Graphics Component Font Parsing Remote Code Execution Vulnerability
CVE-2021-34532
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-34530
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2021-34529
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-34528
Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-34525
Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-34524
Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
CVE-2021-34523
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-34522
Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-34521
Raw Image Extension Remote Code Execution Vulnerability
CVE-2021-34520
Microsoft SharePoint Server Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-3468 A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service which becomes unresponsive after this flaw is triggered. | CVSS3: 5.5 | 0% Низкий | 6 месяцев назад | |
CVE-2021-3467 A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
CVE-2021-34558 The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange allowing a malicious TLS server to cause a TLS client to panic. | CVSS3: 6.5 | 7% Низкий | около 5 лет назад | |
CVE-2021-34556 In the Linux kernel through 5.13.7 an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack. | CVSS3: 5.5 | 0% Низкий | почти 5 лет назад | |
CVE-2021-34537 Windows Bluetooth Driver Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | почти 5 лет назад | |
CVE-2021-34536 Storage Spaces Controller Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 5 лет назад | |
CVE-2021-34535 Remote Desktop Client Remote Code Execution Vulnerability | CVSS3: 8.8 | 18% Средний | почти 5 лет назад | |
CVE-2021-34534 Windows MSHTML Platform Remote Code Execution Vulnerability | CVSS3: 6.8 | 2% Низкий | почти 5 лет назад | |
CVE-2021-34533 Windows Graphics Component Font Parsing Remote Code Execution Vulnerability | CVSS3: 7.8 | 2% Низкий | почти 5 лет назад | |
CVE-2021-34532 ASP.NET Core and Visual Studio Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | почти 5 лет назад | |
CVE-2021-34530 Windows Graphics Component Remote Code Execution Vulnerability | CVSS3: 7.8 | 2% Низкий | почти 5 лет назад | |
CVE-2021-34529 Visual Studio Code Remote Code Execution Vulnerability | 4% Низкий | около 5 лет назад | ||
CVE-2021-34528 Visual Studio Code Remote Code Execution Vulnerability | CVSS3: 7.8 | 3% Низкий | около 5 лет назад | |
CVE-2021-34527 Windows Print Spooler Remote Code Execution Vulnerability | CVSS3: 8.8 | 100% Критический | около 5 лет назад | |
CVE-2021-34525 Windows DNS Server Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | около 5 лет назад | |
CVE-2021-34524 Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability | CVSS3: 8.1 | 3% Низкий | почти 5 лет назад | |
CVE-2021-34523 Microsoft Exchange Server Elevation of Privilege Vulnerability | CVSS3: 9 | 100% Критический | около 5 лет назад | |
CVE-2021-34522 Microsoft Defender Remote Code Execution Vulnerability | 3% Низкий | около 5 лет назад | ||
CVE-2021-34521 Raw Image Extension Remote Code Execution Vulnerability | CVSS3: 7.8 | 2% Низкий | около 5 лет назад | |
CVE-2021-34520 Microsoft SharePoint Server Remote Code Execution Vulnerability | CVSS3: 8.1 | 3% Низкий | около 5 лет назад |
Уязвимостей на страницу