Show filters
1,213 Total Results
Displaying 311-320 of 1,213
Sort by:
Attacker Value
Unknown
CVE-2022-0546
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
0
Attacker Value
Unknown
CVE-2021-3700
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
0
Attacker Value
Unknown
CVE-2021-3610
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
0
Attacker Value
Unknown
CVE-2021-3596
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
0
Attacker Value
Unknown
CVE-2021-26252
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
0
Attacker Value
Unknown
CVE-2021-4115
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
0
Attacker Value
Unknown
CVE-2021-45082
Disclosure Date: February 19, 2022 (last updated February 23, 2025)
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
0
Attacker Value
Unknown
CVE-2022-23645
Disclosure Date: February 18, 2022 (last updated February 23, 2025)
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.
0
Attacker Value
Unknown
CVE-2021-4093
Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for example, outs or ins) using the exit reason SVM_EXIT_IOIO. This issue results in a crash of the entire system or a potential guest-to-host escape scenario.
0
Attacker Value
Unknown
CVE-2021-4091
Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
0