|
197411
|
7.5 |
HIGH
Network
|
openexr debian
|
openexr debian_linux
|
A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerabili…
|
-
|
CVE-2021-20299
|
2024-11-21 14:46 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197412
|
5.5 |
MEDIUM
Local
|
redhat
|
ansible
|
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-20180
|
2024-11-21 14:46 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197413
|
6.5 |
MEDIUM
Local
|
qemu fedoraproject redhat debian
|
qemu fedora enterprise_linux openstack_platform enterprise_linux_for_power_little_endian enterprise_linux_for_ibm_z_systems codeready_linux_builder debian_linux
|
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wi…
|
-
|
CVE-2021-20257
|
2024-11-21 14:46 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197414
|
5.5 |
MEDIUM
Local
|
kexec-tools_project
|
kexec-tools
|
A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The …
|
-
|
CVE-2021-20269
|
2024-11-21 14:46 |
2022-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197415
|
7.8 |
HIGH
Local
|
redhat
|
coreos-installer
|
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead t…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2021-20319
|
2024-11-21 14:46 |
2022-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197416
|
6.1 |
MEDIUM
Local
|
openexr debian
|
openexr debian_linux
|
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an o…
|
-
|
CVE-2021-20303
|
2024-11-21 14:46 |
2022-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197417
|
5.5 |
MEDIUM
Local
|
openexr debian
|
openexr debian_linux
|
A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point excepti…
|
NVD-CWE-noinfo
|
CVE-2021-20302
|
2024-11-21 14:46 |
2022-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197418
|
5.5 |
MEDIUM
Local
|
openexr debian
|
openexr debian_linux
|
A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer …
|
-
|
CVE-2021-20300
|
2024-11-21 14:46 |
2022-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197419
|
4.7 |
MEDIUM
Local
|
linux redhat debian
|
linux_kernel enterprise_linux debian_linux
|
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to crash the syste…
|
CWE-362
Race Condition
|
CVE-2021-20321
|
2024-11-21 14:46 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197420
|
5.5 |
MEDIUM
Local
|
linux fedoraproject redhat
|
linux_kernel fedora enterprise_linux
|
A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may l…
|
NVD-CWE-Other
|
CVE-2021-20320
|
2024-11-21 14:46 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|