|
194241
|
5.5 |
MEDIUM
Local
|
linux fedoraproject debian
|
linux_kernel fedora debian_linux
|
An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.
|
CWE-834
Excessive Iteration
|
CVE-2021-28950
|
2024-11-21 15:00 |
2021-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194242
|
9.8 |
CRITICAL
Network
|
kramdown_project fedoraproject debian
|
kramdown fedora debian_linux
|
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
|
NVD-CWE-noinfo
|
CVE-2021-28834
|
2024-11-21 15:00 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194243
|
7.5 |
HIGH
Network
|
busybox fedoraproject debian
|
busybox fedora debian_linux
|
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-28831
|
2024-11-21 15:00 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194244
|
6.5 |
MEDIUM
Network
|
westerndigital
|
armorlock
|
The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave suppo…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-28653
|
2024-11-21 15:00 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194245
|
6.1 |
MEDIUM
Network
|
increments
|
qiita\
|
Increments Qiita::Markdown before 0.33.0 allows XSS in transformers.
|
CWE-79
Cross-site Scripting
|
CVE-2021-28796
|
2024-11-21 15:00 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194246
|
9.8 |
CRITICAL
Network
|
shellcheck_project
|
shellcheck
|
The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath.
|
NVD-CWE-noinfo
|
CVE-2021-28794
|
2024-11-21 15:00 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194247
|
7.8 |
HIGH
Local
|
swiftformat_project
|
swiftformat
|
The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftformat.path config…
|
CWE-863
Incorrect Authorization
|
CVE-2021-28791
|
2024-11-21 15:00 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194248
|
7.8 |
HIGH
Local
|
swiftlint_project
|
swiftlint
|
The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftlint.path configurat…
|
NVD-CWE-noinfo
|
CVE-2021-28790
|
2024-11-21 15:00 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194249
|
7.8 |
HIGH
Local
|
swift_development_environment_project
|
swift_development_environment
|
The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted sour…
|
NVD-CWE-noinfo
|
CVE-2021-28792
|
2024-11-21 15:00 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194250
|
7.8 |
HIGH
Local
|
apple-swift-format_project
|
apple-swift-format
|
The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted apple-swift-form…
|
NVD-CWE-noinfo
|
CVE-2021-28789
|
2024-11-21 15:00 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|