|
196271
|
6.5 |
MEDIUM
Network
|
python
|
pillow
|
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2021-25292
|
2024-11-21 14:54 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196272
|
7.5 |
HIGH
Network
|
python
|
pillow
|
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
|
CWE-125
Out-of-bounds Read
|
CVE-2021-25291
|
2024-11-21 14:54 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196273
|
7.5 |
HIGH
Network
|
python debian
|
pillow debian_linux
|
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25290
|
2024-11-21 14:54 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196274
|
9.8 |
CRITICAL
Network
|
python
|
pillow
|
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NO…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25289
|
2024-11-21 14:54 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196275
|
6.1 |
MEDIUM
Network
|
suse
|
rancher
|
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: …
|
-
|
CVE-2021-25313
|
2024-11-21 14:54 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196276
|
2.4 |
LOW
Physics
|
samsung
|
internet
|
Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.
|
NVD-CWE-Other
|
CVE-2021-25348
|
2024-11-21 14:54 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196277
|
5.3 |
MEDIUM
Local
|
google
|
android
|
Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is executed.
|
NVD-CWE-noinfo
|
CVE-2021-25347
|
2024-11-21 14:54 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196278
|
9.8 |
CRITICAL
Network
|
google
|
android
|
A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25346
|
2024-11-21 14:54 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196279
|
5.5 |
MEDIUM
Local
|
google
|
android
|
Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format.
|
NVD-CWE-noinfo
|
CVE-2021-25345
|
2024-11-21 14:54 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196280
|
5.5 |
MEDIUM
Local
|
google
|
android
|
Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.
|
CWE-862
Missing Authorization
|
CVE-2021-25344
|
2024-11-21 14:54 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|