Security
Headlines
HeadlinesLatestCVEs

Tag

#dos

CVE-2021-45960: [CVE-2021-45960] A large number of prefixed XML attributes on a single tag can crash libexpat (troublesome left shifts by >=29 bits in function storeAtts) · Issue #531 · libexpat/libexpat

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVE
#vulnerability#mac#dos#git#amd
CVE-2021-45960: A large number of prefixed XML attributes on a single tag can crash libexpat (troublesome left shifts by >=29 bits in function storeAtts) · Issue #531 · libexpat/libexpat

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVE-2021-41817

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

CVE-2021-4190: 2021/CVE-2021-4190.json · master · GitLab.org / cves · GitLab

Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file

CVE-2021-4186: 2021/CVE-2021-4186.json · master · GitLab.org / cves · GitLab

Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVE-2021-4181: 2021/CVE-2021-4181.json · master · GitLab.org / cves · GitLab

Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVE-2021-4184: Wireshark · wnpa-sec-2021-18 · BitTorrent DHT dissector infinite loop

Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVE-2021-4185: Wireshark · wnpa-sec-2021-17 · RTMPT dissector infinite loop

Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVE-2021-4183: 2021/CVE-2021-4183.json · master · GitLab.org / cves · GitLab

Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file

CVE-2021-4182: Wireshark · wnpa-sec-2021-20 · RFC 7468 file parser infinite loop

Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file