CVEs from 2021

4,791 normalized CVEs published or assigned in this year.

Total
4,791
critical
critical 281
high
high 1,022
medium
medium 1,179
low
low 138
% Critical
5.9%
% with KEV
4.4%
% with exploit
5.3%

Top products

  • simatic_wincc_runtime_advanced 28
  • office 13
  • primavera_gateway 10
  • weblogic_server 9
  • primavera_unifier 8
  • modicon_m340_bmxp342020 8
  • log4j 8
  • mbed_tls 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-38291 medium 5.5 FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.
CVE-2021-26259 medium 5.5 A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service.
CVE-2021-20276 medium 5.5 A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.
CVE-2021-21848 medium 5.5 An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The library will actually reuse the parser for at…
CVE-2021-29653 medium 5.5 certificate verification bypass in vault
CVE-2021-21849 medium 5.5 An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an int…
CVE-2021-30154 medium 5.5 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XS…
CVE-2021-30153 medium 5.5 An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an exi…
CVE-2021-30145 medium 5.5 A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.
CVE-2021-29944 medium 5.5 Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue o…
CVE-2021-28421 medium 5.5 arbitrary code execution in fluidsynth
CVE-2021-30156 medium 5.5 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.
CVE-2021-3407 medium 5.5 A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
CVE-2021-22185 medium 5.5 multiple issues in gitlab
CVE-2021-22172 medium 5.5 information disclosure in gitlab
CVE-2021-20308 medium 5.5 Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.
CVE-2021-28041 medium 5.5 ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an …
CVE-2021-23206 medium 5.5 A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
CVE-2021-30577 medium 5.5 Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.
CVE-2021-30586 medium 5.5 Use after free in dialog box handling in Windows in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corrupti…
CVE-2021-30587 medium 5.5 Inappropriate implementation in Compositing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2021-34548 medium 5.5 An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.
CVE-2021-34549 medium 5.5 An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen cir…
CVE-2021-34550 medium 5.5 An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descript…
CVE-2021-40540 medium 5.5 ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check for certain malformed HTTP requests.
CVE-2021-3681 medium 5.5 information disclosure in ansible-core
CVE-2021-46142 medium 5.5 An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
CVE-2021-25218 medium 5.5 In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the circumstances described above, the named process wil…
CVE-2021-21899 medium 5.5 A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow…
CVE-2021-33896 medium 5.5 Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.
CVE-2021-21900 medium 5.5 A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability.…
CVE-2021-37601 medium 5.5 muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common co…
CVE-2021-30474 medium 5.5 multiple issues in aom
CVE-2021-22191 medium 5.5 Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.
CVE-2021-32276 medium 5.5 An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service.
CVE-2021-3623 medium 5.5 A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM …
CVE-2021-32055 medium 5.5 Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set en…
CVE-2021-41805 medium 5.5 HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can …
CVE-2021-30004 medium 5.5 In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
CVE-2021-20275 medium 5.5 A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.
CVE-2021-27229 medium 5.5 arbitrary code execution in mumble
CVE-2021-47670 medium 5.5 10mo ago In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_…
CVE-2021-47457 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: can: isotp: isotp_sendmsg(): add result check for wait_event_interruptible() Using wait_event_interruptible() to wait for complet…
CVE-2021-47505 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: aio: fix use-after-free due to missing POLLFREE handling signalfd_poll() and binder_poll() are special in that they use a waitque…
CVE-2021-47185 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc When running ltp testcase(ltp/testcases/kernel/pty/pty04.c) with arm6…
CVE-2021-47454 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/smp: do not decrement idle task preempt count in CPU offline With PREEMPT_COUNT=y, when a CPU is offlined and then online…
CVE-2021-43612 medium 5.5 2y ago Moderate: lldpd security update
CVE-2021-47098 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations Commit b50aa49638c7 ("hwmon: (lm90) Prevent integer u…
CVE-2021-47429 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix unrecoverable MCE calling async handler from NMI The machine check handler is not considered NMI on 64s. The ear…
CVE-2021-47428 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: fix program check interrupt emergency stack path Emergency stack path was jumping into a 3: label inside the __GEN_C…
CVE-2021-47383 medium 5.5 2y ago Moderate: kernel security update
CVE-2021-47385 medium 5.5 2y ago Moderate: kernel security update
CVE-2021-47459 medium 5.5 2y ago Moderate: kernel security update
CVE-2021-47400 medium 5.5 2y ago Moderate: kernel security and bug fix update
CVE-2021-41092 medium 5.5 2y ago Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configur…
CVE-2021-41089 medium 5.5 2y ago Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted…
CVE-2021-47153 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Don't generate an interrupt on bus reset Now that the i2c-i801 driver supports interrupts, setting the KILL bit in a a…
CVE-2021-46934 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: i2c: validate user data in compat ioctl Wrong user data may cause warning in i2c_transfer(), ex: zero msgs. Userspace should not …
CVE-2021-47055 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK and OTPLOCK modify protection bits. Thus requir…
CVE-2021-47171 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx_bind(). The problem was is non-freed memory in…
CVE-2021-47118 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: pid: take a reference when initializing `cad_pid` During boot, kernel_init_freeable() initializes `cad_pid` to the init task's st…
CVE-2021-47013 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..). If…
CVE-2021-4204 medium 5.5 2y ago An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or l…
CVE-2021-3753 medium 5.5 2y ago A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read in vt as the write access to vc_mode is not protected by lock-in vt_i…
CVE-2021-47316 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: nfsd: fix NULL dereference in nfs3svc_encode_getaclres In error cases the dentry may be NULL. Before 20798dfe249a, the encoder a…
CVE-2021-41244 medium 5.5 2y ago access restriction bypass in grafana
CVE-2021-40153 medium 5.5 2y ago Moderate: squashfs-tools security update
CVE-2021-41072 medium 5.5 2y ago Moderate: squashfs-tools security update
CVE-2021-41043 medium 5.5 2y ago RHSA-2024:0769: tcpdump security update (Moderate)
CVE-2021-29390 medium 5.5 2y ago Moderate: libjpeg-turbo security update
CVE-2021-3382 medium 5.5 2y ago Buffer Overflow in gitea in code.gitea.io/gitea
CVE-2021-47188 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Improve SCSI abort handling The following has been observed on a test setup: WARNING: CPU: 4 PID: 250 at driver…
CVE-2021-47002 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix null pointer dereference in svc_rqst_free() When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scr…
CVE-2021-41091 medium 5.5 2y ago Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirec…
CVE-2021-21334 medium 5.5 2y ago containerd environment variable leak
CVE-2021-3282 medium 5.5 2y ago Improper Authentication in HashiCorp Vault in github.com/hashicorp/vault
CVE-2021-21285 medium 5.5 2y ago In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain…
CVE-2021-21284 medium 5.5 2y ago In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns…
CVE-2021-35937 medium 5.5 2y ago Moderate: rpm security update
CVE-2021-35938 medium 5.5 2y ago Moderate: rpm security update
CVE-2021-35939 medium 5.5 2y ago Moderate: rpm security update
CVE-2021-3468 medium 5.5 3y ago Moderate: avahi security update
CVE-2021-43784 medium 5.5 3y ago Moderate: runc security update
CVE-2021-32142 medium 5.5 3y ago RHSA-2024:2994: LibRaw security update (Moderate)
CVE-2021-3502 medium 5.5 3y ago Moderate: avahi security update
CVE-2021-33646 medium 5.5 3y ago RHSA-2023:2898: libtar security update (Moderate)
CVE-2021-33644 medium 5.5 3y ago RHSA-2023:2898: libtar security update (Moderate)
CVE-2021-33645 medium 5.5 3y ago RHSA-2023:2898: libtar security update (Moderate)
CVE-2021-33643 medium 5.5 3y ago RHSA-2023:2898: libtar security update (Moderate)
CVE-2021-3782 medium 5.5 3y ago RHSA-2023:2786: wayland security, bug fix, and enhancement update (Moderate)
CVE-2021-44648 medium 5.5 3y ago Moderate: gdk-pixbuf2 security update
CVE-2021-46829 medium 5.5 3y ago Moderate: gdk-pixbuf2 security update
CVE-2021-46790 medium 5.5 3y ago RHSA-2023:2757: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
CVE-2021-46822 medium 5.5 3y ago Moderate: libjpeg-turbo security update
CVE-2021-43519 medium 5.5 3y ago Moderate: lua security update
CVE-2021-44964 medium 5.5 3y ago Moderate: lua security update
CVE-2021-46848 medium 5.5 3y ago RHSA-2023:0116: libtasn1 security update (Moderate)
CVE-2021-44906 medium 5.5 3y ago RHSA-2023:0050: nodejs:14 security, bug fix, and enhancement update (Moderate)
CVE-2021-33621 medium 5.5 4y ago RHSA-2024:3500: ruby:3.0 security update (Moderate)
CVE-2021-33195 medium 5.5 4y ago RHSA-2021:4226: grafana security, bug fix, and enhancement update (Moderate)