|
561
|
7.0
5.1
|
HIGH
Local
|
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature …
|
-
|
CVE-2021-20271
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 14:46
2021-03-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
562
|
5.3
5.0
|
MEDIUM
Network
|
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of a…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-35518
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 14:27
2021-03-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
563
|
6.3
3.3
|
MEDIUM
Local
|
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (pre…
|
-
|
CVE-2021-20197
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 14:46
2021-03-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
564
|
4.5
4.4
|
MEDIUM
Local
|
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local…
|
-
|
CVE-2020-35508
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 14:27
2021-03-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
565
|
9.8
10.0
|
CRITICAL
Network
|
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that…
|
-
|
CVE-2021-3466
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 15:21
2021-03-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
566
|
5.5
2.1
|
MEDIUM
Local
|
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain s…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-3446
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 15:21
2021-03-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
567
|
5.5
4.3
|
MEDIUM
Local
|
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an appl…
|
-
|
CVE-2021-3443
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 15:21
2021-03-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
568
|
5.7
4.6
|
MEDIUM
Local
|
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-3409
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 15:21
2021-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
569
|
7.5
5.0
|
HIGH
Network
|
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-20270
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 14:46
2021-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
570
|
9.8
9.0
|
CRITICAL
Network
|
A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a De…
|
-
|
CVE-2019-10196
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 13:18
2021-03-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|