CVEs from 2021

4,786 normalized CVEs published or assigned in this year.

Total
4,786
critical
critical 281
high
high 1,022
medium
medium 1,179
low
low 138
% Critical
5.9%
% with KEV
4.5%
% with exploit
5.3%

Top products

  • simatic_wincc_runtime_advanced 28
  • office 13
  • primavera_gateway 10
  • weblogic_server 9
  • primavera_unifier 8
  • modicon_m340_bmxp342020 8
  • log4j 8
  • mbed_tls 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-36690 low 2.5 A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance o…
CVE-2021-1405 low 2.5 A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service con…
CVE-2021-3474 low 2.5 There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with app…
CVE-2021-3443 low 2.5 denial of service in jasper
CVE-2021-37616 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. …
CVE-2021-34335 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A floating point exception (FPE) due to an integer divide by zero was found …
CVE-2021-32613 low 2.5 In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
CVE-2021-27212 low 2.5 In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemo…
CVE-2021-3671 low 2.5 A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samb…
CVE-2021-27375 low 2.5 insufficient validation in traefik
CVE-2021-3974 low 2.5 vim is vulnerable to Use After Free
CVE-2021-39929 low 2.5 Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-32275 low 2.5 An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in cosprim.hh. It allows an attacker to cause Denial of Service.
CVE-2021-28039 low 2.5 An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of…
CVE-2021-39924 low 2.5 Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-39922 low 2.5 Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-32815 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata…
CVE-2021-30046 low 2.5 denial of service in vigra
CVE-2021-30218 low 2.5 denial of service in samurai
CVE-2021-28089 low 2.5 Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
CVE-2021-39220 low 2.5 information disclosure in nextcloud-app-mail
CVE-2021-3178 low 2.5 fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPL…
CVE-2021-30219 low 2.5 denial of service in samurai
CVE-2021-33500 low 2.5 PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetW…
CVE-2021-28831 low 2.5 decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
CVE-2021-38373 low 2.5 In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
CVE-2021-3673 low 2.5 A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS.
CVE-2021-20193 low 2.5 A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat fro…
CVE-2021-36769 low 2.5 content spoofing in telegram-desktop
CVE-2021-39926 low 2.5 Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
CVE-2021-3927 low 2.5 vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-35331 low 2.5 In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding
CVE-2021-39921 low 2.5 NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-39920 low 2.5 NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
CVE-2021-22174 low 2.5 Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
CVE-2021-4023 low 2.5 A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-urin…
CVE-2021-3875 low 2.5 vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3928 low 2.5 vim is vulnerable to Use of Uninitialized Variable
CVE-2021-41865 low 2.5 denial of service in nomad
CVE-2021-43877 low 2.5 privilege escalation in dotnet-runtime
CVE-2021-3968 low 2.5 vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-39247 low 2.5 Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs_encode_uint in reedsol.c.
CVE-2021-3467 low 2.5 denial of service in jasper
CVE-2021-37621 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini…
CVE-2021-3973 low 2.5 vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3477 low 2.5 There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer over…
CVE-2021-36367 low 2.5 PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a l…
CVE-2021-4069 low 2.5 vim is vulnerable to Use After Free
CVE-2021-26934 low 2.5 An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration…
CVE-2021-34183 low 2.5 denial of service in imagemagick
CVE-2021-39928 low 2.5 NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-39925 low 2.5 Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-3903 low 2.5 2y ago vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-26086 unknown 2.5 2y ago Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
CVE-2021-44529 unknown 2.5 2y ago Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
CVE-2021-3826 low 2.5 3y ago Low: gdb security update
CVE-2021-43618 low 2.5 3y ago Low: gmp security and enhancement update
CVE-2021-27876 unknown 2.5 3y ago Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Ag…
CVE-2021-27877 unknown 2.5 3y ago Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.
CVE-2021-27878 unknown 2.5 3y ago Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.
CVE-2021-35587 unknown 2.5 4y ago Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
CVE-2021-44269 low 2.5 4y ago RHSA-2022:7558: wavpack security update (Low)
CVE-2021-46195 low 2.5 4y ago Low: mingw-gcc security and bug fix update
CVE-2021-3507 low 2.5 4y ago A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers fr…
CVE-2021-3493 unknown 2.5 4y ago The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
CVE-2021-3981 low 2.5 4y ago RHSA-2022:2110: grub2 security, bug fix, and enhancement update (Low)
CVE-2021-3634 low 2.5 4y ago RHSA-2022:2031: libssh security, bug fix, and enhancement update (Low)
CVE-2021-3802 low 2.5 4y ago RHSA-2022:1820: udisks2 security and bug fix update (Low)
CVE-2021-41229 low 2.5 4y ago RHSA-2022:2081: bluez security update (Low)
CVE-2021-23222 low 2.5 4y ago RHSA-2022:1891: libpq security update (Low)
CVE-2021-31166 unknown 2.5 4y ago Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
CVE-2021-3461 low 2.5 4y ago Keycloak insufficient session expiration
CVE-2021-21551 unknown 2.5 4y ago Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
CVE-2021-26085 unknown 2.5 4y ago Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
CVE-2021-42237 unknown 2.5 4y ago Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
CVE-2021-4091 low 2.5 4y ago RHSA-2022:0889: 389-ds:1.4 security and bug fix update (Low)
CVE-2021-36934 unknown 2.5 4y ago If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
CVE-2021-25298 unknown 2.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-25297 unknown 2.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-25296 unknown 2.5 4y ago Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.
CVE-2021-21975 unknown 2.5 4y ago Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to s…
CVE-2021-36260 unknown 2.5 5y ago A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
CVE-2021-20257 low 2.5 5y ago An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized wi…
CVE-2021-3930 low 2.5 5y ago An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). …
CVE-2021-45046 unknown 2.5 5y ago Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in…
CVE-2021-44077 unknown 2.5 5y ago Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution
CVE-2021-43668 low 2.5 5y ago Denial of Service in Go-Ethereum
CVE-2021-42321 unknown 2.5 5y ago An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-40449 unknown 2.5 5y ago Unspecified vulnerability allows for an authenticated user to escalate privileges.
CVE-2021-3572 low 2.5 5y ago A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest…
CVE-2021-20266 low 2.5 5y ago RHSA-2021:4489: rpm security, bug fix, and enhancement update (Low)
CVE-2021-3200 low 2.5 5y ago Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c…
CVE-2021-43566 low 2.5 5y ago RHBA-2021:4438: samba bug fix and enhancement update (Low)
CVE-2021-20269 low 2.5 5y ago RHSA-2021:4404: kexec-tools security, bug fix, and enhancement update (Low)
CVE-2021-22005 unknown 2.5 5y ago VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
CVE-2021-1675 unknown 2.5 5y ago Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-38648 unknown 2.5 5y ago Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
CVE-2021-21985 unknown 2.5 5y ago VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code executio…
CVE-2021-40539 unknown 2.5 5y ago Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
CVE-2021-26855 unknown 2.5 5y ago Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.