Show filters
486 Total Results
Displaying 91-100 of 486
Sort by:
Attacker Value
Unknown
CVE-2021-4182
Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
0
Attacker Value
Unknown
CVE-2021-4185
Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
0
Attacker Value
Unknown
CVE-2021-4183
Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
0
Attacker Value
Unknown
CVE-2021-4181
Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
0
Attacker Value
Unknown
CVE-2021-4184
Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
0
Attacker Value
Unknown
CVE-2021-44224
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
0
Attacker Value
Unknown
CVE-2021-23797
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.
0
Attacker Value
Unknown
CVE-2021-43818
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.
0
Attacker Value
Unknown
CVE-2021-42717
Disclosure Date: December 07, 2021 (last updated February 23, 2025)
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
0
Attacker Value
Unknown
CVE-2021-42697
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.
0