|
421
|
6.5
4.0
|
MEDIUM
Network
|
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression D…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-3733
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
422
|
7.5
7.1
|
HIGH
Network
|
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinit…
|
CWE-400 CWE-835
Uncontrolled Resource Consumption Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-3737
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 15:22
2022-03-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
423
|
8.8
7.2
|
HIGH
Local
|
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a ne…
|
CWE-862
Missing Authorization
|
CVE-2021-3656
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
424
|
7.8
6.8
|
HIGH
Local
|
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permission…
|
-
|
CVE-2021-3575
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 15:21
2022-03-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
425
|
8.1
5.1
|
HIGH
Network
|
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection …
|
-
|
CVE-2021-23214
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 14:51
2022-03-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
426
|
7.8
6.9
|
HIGH
Local
|
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_…
|
CWE-862
Missing Authorization
|
CVE-2022-0492
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:38
2022-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
427
|
5.5
2.1
|
MEDIUM
Local
|
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest th…
|
-
|
CVE-2021-3620
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
428
|
5.5
1.9
|
MEDIUM
Local
|
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment varia…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2021-3602
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:21
2022-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
429
|
3.1
3.5
|
LOW
Network
|
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY bef…
|
NVD-CWE-Other
|
CVE-2021-3716
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
430
|
6.5
5.8
|
MEDIUM
Network
|
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used a…
|
-
|
CVE-2021-3772
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|