Show filters
1,213 Total Results
Displaying 341-350 of 1,213
Sort by:
Attacker Value
Unknown
CVE-2021-46141
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
0
Attacker Value
Unknown
CVE-2021-41819
Disclosure Date: January 01, 2022 (last updated February 23, 2025)
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
0
Attacker Value
Unknown
CVE-2021-41817
Disclosure Date: January 01, 2022 (last updated February 23, 2025)
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
0
Attacker Value
Unknown
CVE-2021-23727
Disclosure Date: December 29, 2021 (last updated February 23, 2025)
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.
0
Attacker Value
Unknown
CVE-2021-44832
Disclosure Date: December 28, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
0
Attacker Value
Unknown
CVE-2021-4166
Disclosure Date: December 25, 2021 (last updated February 23, 2025)
vim is vulnerable to Out-of-bounds Read
0
Attacker Value
Unknown
CVE-2021-3622
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2021-3621
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
0
Attacker Value
Unknown
CVE-2021-4024
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.
0
Attacker Value
Unknown
CVE-2021-45463
Disclosure Date: December 23, 2021 (last updated October 07, 2023)
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
0