Show filters
977 Total Results
Displaying 41-50 of 977
Sort by:
Attacker Value
Unknown

CVE-2021-3426

Disclosure Date: May 20, 2021 (last updated November 08, 2023)
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.
Attacker Value
Unknown

CVE-2021-3421

Disclosure Date: May 19, 2021 (last updated November 08, 2023)
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.
Attacker Value
Unknown

CVE-2021-3531

Disclosure Date: May 18, 2021 (last updated October 24, 2023)
A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.
Attacker Value
Unknown

CVE-2021-3524

Disclosure Date: May 17, 2021 (last updated October 24, 2023)
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.
Attacker Value
Unknown

CVE-2021-32919

Disclosure Date: May 13, 2021 (last updated November 08, 2023)
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
Attacker Value
Unknown

CVE-2021-32918

Disclosure Date: May 13, 2021 (last updated November 08, 2023)
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
Attacker Value
Unknown

CVE-2021-32917

Disclosure Date: May 13, 2021 (last updated November 08, 2023)
An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
Attacker Value
Unknown

CVE-2021-32920

Disclosure Date: May 13, 2021 (last updated November 08, 2023)
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
Attacker Value
Unknown

CVE-2021-32921

Disclosure Date: May 13, 2021 (last updated November 08, 2023)
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
Attacker Value
Unknown

CVE-2020-27823

Disclosure Date: May 13, 2021 (last updated November 08, 2023)
A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.