CVEs from 2021

6,232 normalized CVEs published or assigned in this year.

Total
6,232
critical
critical 273
high
high 975
medium
medium 1,141
low
low 135
% Critical
4.4%
% with KEV
3.4%
% with exploit
3.4%

Top products

  • office 13
  • 365_apps 6
  • office_long_term_servicing_channel 6
  • library_automation_system 5
  • single_connect 4
  • http_server 3
  • solidfire 2
  • student_information_management_system 2
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2021-22207 low 2.5 Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file archsusedebian
CVE-2021-22235 low 2.5 Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file archsusedebian
CVE-2021-39929 low 2.5 Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file archsusedebian
CVE-2021-28039 low 2.5 An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of… archsusedebian
CVE-2021-30178 low 2.5 An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987. archsusedebian
CVE-2021-3476 low 2.5 A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially aff… archsusedebian
CVE-2021-3478 low 2.5 There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory… archsusedebian
CVE-2021-20296 low 2.5 A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could ca… archsusedebian
CVE-2021-36690 low 2.5 A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance o… archsusedebian
CVE-2021-4023 low 2.5 A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-urin… archsusedebian
CVE-2021-20217 low 2.5 A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system a… archdebian
CVE-2021-31855 low 2.5 KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) caus… archdebian
CVE-2021-30219 low 2.5 denial of service in samurai arch
CVE-2021-4110 low 2.5 mruby is vulnerable to NULL Pointer Dereference archdebian
CVE-2021-28117 low 2.5 libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of… archdebian
CVE-2021-3928 low 2.5 vim is vulnerable to Use of Uninitialized Variable archsusedebian
CVE-2021-39247 low 2.5 Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs_encode_uint in reedsol.c. archdebian
CVE-2021-4021 low 2.5 A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled res… archdebian
CVE-2021-43877 low 2.5 privilege escalation in dotnet-runtime arch
CVE-2021-3968 low 2.5 vim is vulnerable to Heap-based Buffer Overflow archdebian
CVE-2021-33500 low 2.5 PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetW… archdebian
CVE-2021-32613 low 2.5 In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS. archdebian
CVE-2021-32719 low 2.5 RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` … archsusedebian
CVE-2021-32718 low 2.5 RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation mess… archsusedebian
CVE-2021-20177 low 2.5 A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can pa… archsusedebian
CVE-2021-35331 low 2.5 In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding archdebian
CVE-2021-22222 low 2.5 Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file archdebian
CVE-2021-22897 low 2.5 curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The s… archdebian
CVE-2021-37615 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. … archdebiansuse
CVE-2021-3443 low 2.5 denial of service in jasper archsuse
CVE-2021-23239 low 2.5 The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled… archsuserockylinuxdebian
CVE-2021-36367 low 2.5 PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a l… archdebian
CVE-2021-20216 low 2.5 A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is t… archdebian
CVE-2021-3477 low 2.5 There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer over… archsusedebian
CVE-2021-23240 low 2.5 selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary … archsuserockylinuxdebian
CVE-2021-37620 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The o… archdebiansuse
CVE-2021-3658 low 2.5 bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discov… debianarchsuse
CVE-2021-21300 low 2.5 Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as… archsusedebian
CVE-2021-1404 low 2.5 A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an… archdebiansuse
CVE-2021-3652 low 2.5 Low: 389-ds:1.4 security and bug fix update debianarchsuserockylinux
CVE-2021-37622 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini… archdebiansuse
CVE-2021-38604 low 2.5 In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was… archsusedebian
CVE-2021-20205 low 2.5 Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image. archdebian
CVE-2021-28090 low 2.5 Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002. archdebian
CVE-2021-34813 low 2.5 Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has … archdebian
CVE-2021-28089 low 2.5 Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001. archdebian
CVE-2021-3673 low 2.5 A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS. archdebian
CVE-2021-41865 low 2.5 denial of service in nomad arch
CVE-2021-36769 low 2.5 A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the server to receive messages in a different o… archdebian
CVE-2021-3973 low 2.5 vim is vulnerable to Heap-based Buffer Overflow archdebian
CVE-2021-3671 low 2.5 A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samb… archsusedebian
CVE-2021-30046 low 2.5 denial of service in vigra arch
CVE-2021-30218 low 2.5 denial of service in samurai arch
CVE-2021-40985 low 2.5 A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp. archsusedebian
CVE-2021-4069 low 2.5 vim is vulnerable to Use After Free archsusedebian
CVE-2021-42917 low 2.5 Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper length of values passed to istream. archdebian
CVE-2021-39928 low 2.5 NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file archsusedebian
CVE-2021-39925 low 2.5 Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file archsusedebian
CVE-2021-39924 low 2.5 Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file archsusedebian
CVE-2021-37616 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. … archdebiansuse
CVE-2021-34335 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A floating point exception (FPE) due to an integer divide by zero was found … archdebiansuse
CVE-2021-3927 low 2.5 vim is vulnerable to Heap-based Buffer Overflow archsusedebian
CVE-2021-39922 low 2.5 Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file archsusedebian
CVE-2021-37621 low 2.5 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini… archdebiansuse
CVE-2021-26934 low 2.5 An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration… archsusedebian
CVE-2021-1405 low 2.5 A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service con… archdebiansuse
CVE-2021-3479 low 2.5 There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption o… archsusedebian
CVE-2021-27815 low 2.5 NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicio… archsusedebian
CVE-2021-3903 low 2.5 2y ago Low: vim security update redhatarchsuserockylinux+1
CVE-2021-43618 low 2.5 3y ago Low: gmp security and enhancement update redhatarchsusedebian
CVE-2021-3826 low 2.5 3y ago Low: gdb security update redhatdebiansuse
CVE-2021-28153 low 2.5 4y ago Low: mingw-glib2 security and bug fix update redhatarchsusedebian+1
CVE-2021-46195 low 2.5 4y ago Low: mingw-gcc security and bug fix update redhatdebiansuse
CVE-2021-44269 low 2.5 4y ago Low: wavpack security update redhatsuserockylinuxdebian
CVE-2021-47076 low 2.5 4y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Return CQE error if invalid lkey was supplied RXE is missing update of WQE status in LOCAL_WRITE failures. This caused… redhatsusedebian
CVE-2021-3981 low 2.5 4y ago Low: grub2 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2021-3634 low 2.5 4y ago Low: libssh security, bug fix, and enhancement update archsuserockylinuxdebian
CVE-2021-3802 low 2.5 4y ago Low: udisks2 security and bug fix update suserockylinuxdebian
CVE-2021-41229 low 2.5 4y ago Low: bluez security update debianarchsuserockylinux
CVE-2021-23222 low 2.5 4y ago Low: libpq security update archsuserockylinuxdebian
CVE-2021-43813 low 2.5 4y ago Low: grafana security, bug fix, and enhancement update archsuserockylinux
CVE-2021-3461 low 2.5 4y ago Keycloak insufficient session expiration archjava
CVE-2021-4091 low 2.5 4y ago Low: 389-ds:1.4 security and bug fix update debiansuserockylinux
CVE-2021-20257 low 2.5 5y ago Low: virt:rhel and virt-devel:rhel security update suserockylinuxdebian
CVE-2021-3930 low 2.5 5y ago Low: virt:rhel and virt-devel:rhel security update suserockylinuxdebian
CVE-2021-43668 low 2.5 5y ago Denial of Service in Go-Ethereum archgolang
CVE-2021-20266 low 2.5 5y ago Low: rpm security, bug fix, and enhancement update suserockylinuxdebian
CVE-2021-3200 low 2.5 5y ago Low: libsolv security and bug fix update suserockylinuxdebian
CVE-2021-3828 low 2.5 5y ago nltk is vulnerable to Inefficient Regular Expression Complexity archdebianpython
CVE-2021-37860 low 2.5 5y ago Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server archgolang
CVE-2021-25740 low 2.5 5y ago A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. archsusedebiangolang
CVE-2021-40839 low 2.5 5y ago The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory. archdebianpython
CVE-2021-25737 low 2.5 5y ago A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or … archsusedebiangolang
CVE-2021-23437 low 2.5 5y ago The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. archsusedebianpython
CVE-2021-29063 low 2.5 5y ago A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 when the mpmathify function is called. archdebianpython
CVE-2021-32813 low 2.5 5y ago Header dropping in traefik in github.com/traefik/traefik archgolang
CVE-2021-36374 low 2.5 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant debianarchsusejava
CVE-2021-36373 low 2.5 5y ago Improper Handling of Length Parameter Inconsistency in Apache Ant debianarchsusejava
CVE-2021-21303 low 2.5 5y ago Insufficient sanitization of data files in helm.sh/helm/v3 archgolang
CVE-2021-31542 low 2.5 5y ago In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names. archsusedebianpython