2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0891HIGH7.5An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Pro...
CVE-2021-0887MEDIUM5.5In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This co...
CVE-2021-0698MEDIUM5.5In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could...
CVE-2021-3997MEDIUM5.5A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time ...
CVE-2021-3996MEDIUM5.5A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmoun...
CVE-2021-3995MEDIUM5.5A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmoun...
CVE-2021-3975MEDIUM6.5A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is calle...
CVE-2021-3917MEDIUM5.5A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable a...
CVE-2021-3905HIGH7.5A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this f...
CVE-2021-3894Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-3839HIGH7.5A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inf...
CVE-2021-3827MEDIUM6.8A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By ex...
CVE-2021-3800MEDIUM5.5A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by...
CVE-2021-3798MEDIUM5.5A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is cre...
CVE-2021-3771Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-3764MEDIUM5.5A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a den...
CVE-2021-3763MEDIUM4.3A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access so...
CVE-2021-3759MEDIUM5.5A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a u...
CVE-2021-3736MEDIUM5.5A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in V...
CVE-2021-3724Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-3714MEDIUM5.9A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication ...
CVE-2021-3702MEDIUM6.3A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a te...
CVE-2021-3701MEDIUM6.6A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world...
CVE-2021-3690HIGH7.5A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This f...
CVE-2021-3670MEDIUM6.5MaxQueryDuration not honoured in Samba AD DC LDAP

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now