2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41690 | HIGH | 7.5 | 1.6% | Jun 28, 2022 | DCMTK through 3.6.6 does not handle memory free properly. The malloced memory for storing all file information are recor... |
| CVE-2021-41689 | HIGH | 7.5 | 1.7% | Jun 28, 2022 | DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would que... |
| CVE-2021-41688 | HIGH | 7.5 | 1.6% | Jun 28, 2022 | DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still use... |
| CVE-2021-41687 | HIGH | 7.5 | 1.6% | Jun 28, 2022 | DCMTK through 3.6.6 does not handle memory free properly. The program malloc a heap memory for parsing data, but does no... |
| CVE-2021-41460 | HIGH | 7.5 | 6.8% | Jun 28, 2022 | ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information. |
| CVE-2021-40944 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_... |
| CVE-2021-40943 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in A... |
| CVE-2021-40609 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box ... |
| CVE-2021-40608 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in ... |
| CVE-2021-40607 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box ... |
| CVE-2021-40606 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4B... |
| CVE-2021-40942 | MEDIUM | 5.5 | 0.6% | Jun 27, 2022 | In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filter_parse_dyn_args function in filter_core/fil... |
| CVE-2021-40941 | HIGH | 7.5 | 1.1% | Jun 27, 2022 | In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapaci... |
| CVE-2021-33654 | HIGH | 7.5 | 0.8% | Jun 27, 2022 | When performing the initialization operation of the Split operator, if a dimension in the input shape is 0, it will caus... |
| CVE-2021-33653 | HIGH | 7.5 | 0.8% | Jun 27, 2022 | When performing the derivation shape operation of the SpaceToBatch operator, if there is a value of 0 in the parameter b... |
| CVE-2021-33652 | HIGH | 7.5 | 0.8% | Jun 27, 2022 | When the Reduce operator run operation is executed, if there is a value of 0 in the parameter axis_sizes element, it wil... |
| CVE-2021-33651 | HIGH | 7.5 | 0.8% | Jun 27, 2022 | When performing the analytical operation of the DepthwiseConv2D operator, if the attribute depth_multiplier is 0, it wil... |
| CVE-2021-33650 | HIGH | 7.5 | 0.9% | Jun 27, 2022 | When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three,... |
| CVE-2021-33649 | HIGH | 7.5 | 0.9% | Jun 27, 2022 | When performing the inference shape operation of the Transpose operator, if the value in the perm element is greater tha... |
| CVE-2021-33648 | HIGH | 7.5 | 0.9% | Jun 27, 2022 | When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operator... |
| CVE-2021-33647 | HIGH | 7.5 | 0.9% | Jun 27, 2022 | When performing the inference shape operation of the Tile operator, if the input data type is not int or int32, it will ... |
| CVE-2021-40901 | HIGH | 7.5 | 1.0% | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating c... |
| CVE-2021-40900 | HIGH | 7.5 | 1.0% | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted in... |
| CVE-2021-40899 | HIGH | 7.5 | 1.1% | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloadi... |
| CVE-2021-40898 | HIGH | 7.5 | 1.0% | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying craft... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now