2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-4218MEDIUM5.5A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panic...
CVE-2021-4217LOW3.3A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a nul...
CVE-2021-4214MEDIUM5.5A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to...
CVE-2021-4213HIGH7.5A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the ser...
CVE-2021-4209MEDIUM6.5A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing...
CVE-2021-4204HIGH7.1An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This...
CVE-2021-4189MEDIUM5.3A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The ...
CVE-2021-4178MEDIUM6.7A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. D...
CVE-2021-4159MEDIUM4.4A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory lo...
CVE-2021-4158MEDIUM6A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could...
CVE-2021-4155MEDIUM5.5A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files wit...
CVE-2021-4142MEDIUM5.5The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an...
CVE-2021-4125HIGH8.1It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers...
CVE-2021-4122MEDIUM4.3It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery o...
CVE-2021-4041HIGH7.8A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interfac...
CVE-2021-4040MEDIUM5.3A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out...
CVE-2021-4037MEDIUM4.4A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local user...
CVE-2021-4028HIGH7.8A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local ...
CVE-2021-43309HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when ...
CVE-2021-3999HIGH7.8A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when th...
CVE-2021-3998HIGH7.5A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to inf...
CVE-2021-3488Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-39815CRITICAL9.8The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre...
CVE-2021-0947HIGH7.5The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLSer...
CVE-2021-0946HIGH7.5The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer v...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now