Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2021-43332
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could…
Debian Linux
2.1.36+
MEDIUM 6.1
CVE-2021-43331
In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.
Debian Linux
2.1.36+
MEDIUM 6.5
CVE-2021-3911
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
Debian Linux
1.3.0+
MEDIUM 6.5
CVE-2021-3912
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to creat…
Debian Linux
1.3.0+
CRITICAL 9.8
CVE-2021-3907
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr…
Debian Linux
1.3.0+
HIGH 7.5
CVE-2021-3908
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal ne…
Debian Linux
1.3.0+
HIGH 7.5
CVE-2021-3909
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically…
Debian Linux
1.3.0+
HIGH 7.5
CVE-2021-3910
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
Debian Linux
1.4.0+
HIGH 7.5
CVE-2021-43173
In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feedin…
Debian Linux
0.10.2+
HIGH 7.5
CVE-2021-43174
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding ca…
Debian Linux
0.10.2+
HIGH 7.5
CVE-2021-43114
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers …
Debian Linux
1.5.2+
CRITICAL 9.1
CVE-2021-43400
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu…
Debian Linux
Patch available
MEDIUM 6.5
CVE-2021-22960
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smug…
Debian Linux
2.1.4 / 6.0.6+
MEDIUM 5.5
CVE-2021-40985
A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.
Debian Linux
1.9.12+
MEDIUM 5.9
CVE-2021-38502
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept trans…
Debian Linux
91.2+
MEDIUM 5.3
CVE-2021-25219EPSS 8%
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as we…
Debian Linux
9.11.36 / 9.16.22+
HIGH 8.0
CVE-2021-42097
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain …
Debian Linux
2.1.35+
HIGH 7.8
CVE-2021-42771
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversa…
Debian Linux
2.9.1+
HIGH 7.5
CVE-2021-37136EPSS 6%
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size u…
Debian Linux
2.2.4 / 4.1.68+
HIGH 7.5
CVE-2021-37137EPSS 7%
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved…
Debian Linux
4.1.68 / 12.0.0.4.6+
HIGH 7.5
CVE-2021-41990EPSS 7%
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can…
Debian Linux
5.9.4+
HIGH 7.5
CVE-2021-41991EPSS 5%
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to …
Debian Linux
5.9.4+
MEDIUM 6.1
CVE-2021-40732
XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memor…
Debian Linux
after 2020.1
MEDIUM 5.3
CVE-2021-42326
Redmine before 4.1.5 and 4.2.x before 4.2.3 may disclose the names of users on activity views due to an insufficient access filter.
Debian Linux
4.1.5 / 4.2.3+
MEDIUM 6.5
CVE-2021-3671
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authen…
Debian Linux
4.13.12 / 4.14.8+
HIGH 7.5
CVE-2021-25634
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…
Debian Linux
7.0.6 / 7.1.2+
HIGH 7.5
CVE-2021-42260
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a cr…
Debian Linux
after 2.6.2
HIGH 7.5
CVE-2021-25633
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…
Debian Linux
7.0.6 / 7.1.2+
HIGH 7.8
CVE-2021-41133
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak …
Debian Linux
1.8.2 / 1.10.4+
MEDIUM 6.5
CVE-2021-41125
Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider a…
Debian Linux
1.8.1 / 2.5.1+