Show filters
105 Total Results
Displaying 51-60 of 105
Sort by:
Attacker Value
Unknown
CVE-2021-37714
Disclosure Date: August 18, 2021 (last updated February 23, 2025)
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.
0
Attacker Value
Unknown
CVE-2021-38202
Disclosure Date: August 08, 2021 (last updated February 23, 2025)
fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd.
0
Attacker Value
Unknown
CVE-2021-38203
Disclosure Date: August 08, 2021 (last updated February 23, 2025)
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
0
Attacker Value
Unknown
CVE-2021-38199
Disclosure Date: August 08, 2021 (last updated November 28, 2024)
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.
0
Attacker Value
Unknown
CVE-2021-38201
Disclosure Date: August 08, 2021 (last updated February 23, 2025)
net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 READ_PLUS operations.
0
Attacker Value
Unknown
CVE-2021-38160
Disclosure Date: August 07, 2021 (last updated February 23, 2025)
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior
0
Attacker Value
Unknown
CVE-2021-22118
Disclosure Date: May 27, 2021 (last updated February 22, 2025)
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.
0
Attacker Value
Unknown
CVE-2021-26987
Disclosure Date: March 15, 2021 (last updated November 28, 2024)
Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56 and Management Node versions through 12.2 contain vulnerable versions of SpringBoot Framework.
0
Attacker Value
Unknown
CVE-2020-27223
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
0
Attacker Value
Unknown
CVE-2020-29368
Disclosure Date: November 28, 2020 (last updated February 22, 2025)
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
0