|
431
|
6.5
4.0
|
MEDIUM
Network
|
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The …
|
-
|
CVE-2021-3677
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
432
|
6.5
3.5
|
MEDIUM
Network
|
An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not prop…
|
-
|
CVE-2021-3667
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
433
|
6.3
3.3
|
MEDIUM
Local
|
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the bre…
|
-
|
CVE-2021-3631
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
434
|
6.1
3.6
|
MEDIUM
Local
|
A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-3623
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:22
2022-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
435
|
7.5
5.0
|
HIGH
Network
|
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loo…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2022-0711
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 15:39
2022-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
436
|
6.4
4.4
|
MEDIUM
Local
|
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts…
|
CWE-416
Use After Free
|
CVE-2021-3700
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 15:22
2022-02-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
437
|
7.5
5.0
|
HIGH
Network
|
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array si…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-3610
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:21
2022-02-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
438
|
6.5
4.3
|
MEDIUM
Network
|
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreateP…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-3596
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 15:21
2022-02-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
439
|
7.8
6.8
|
HIGH
Local
|
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-26252
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 14:55
2022-02-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
440
|
5.5
2.1
|
MEDIUM
Local
|
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE…
|
NVD-CWE-Other
|
CVE-2021-4115
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:36
2022-02-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|