Show filters
977 Total Results
Displaying 51-60 of 977
Sort by:
Attacker Value
Unknown

CVE-2020-25713

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
Attacker Value
Unknown

CVE-2020-27824

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-27840

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-20277

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-32606

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)
Attacker Value
Unknown

CVE-2021-31204

Disclosure Date: May 11, 2021 (last updated November 28, 2024)
.NET and Visual Studio Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2021-31829

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.
Attacker Value
Unknown

CVE-2021-20254

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those values into the process token that stores the group membership for a user. The highest threat from this vulnerability is to data confidentiality and integrity.
Attacker Value
Unknown

CVE-2021-31800

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.
Attacker Value
Unknown

CVE-2021-21227

Disclosure Date: April 30, 2021 (last updated February 22, 2025)
Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.