2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41690HIGH7.5DCMTK through 3.6.6 does not handle memory free properly. The malloced memory for storing all file information are recor...
CVE-2021-41689HIGH7.5DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would que...
CVE-2021-41688HIGH7.5DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still use...
CVE-2021-41687HIGH7.5DCMTK through 3.6.6 does not handle memory free properly. The program malloc a heap memory for parsing data, but does no...
CVE-2021-41460HIGH7.5ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
CVE-2021-40944MEDIUM5.5In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_...
CVE-2021-40943MEDIUM5.5In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in A...
CVE-2021-40609MEDIUM5.5The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box ...
CVE-2021-40608MEDIUM5.5The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in ...
CVE-2021-40607MEDIUM5.5The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box ...
CVE-2021-40606MEDIUM5.5The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4B...
CVE-2021-40942MEDIUM5.5In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filter_parse_dyn_args function in filter_core/fil...
CVE-2021-40941HIGH7.5In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapaci...
CVE-2021-33654HIGH7.5When performing the initialization operation of the Split operator, if a dimension in the input shape is 0, it will caus...
CVE-2021-33653HIGH7.5When performing the derivation shape operation of the SpaceToBatch operator, if there is a value of 0 in the parameter b...
CVE-2021-33652HIGH7.5When the Reduce operator run operation is executed, if there is a value of 0 in the parameter axis_sizes element, it wil...
CVE-2021-33651HIGH7.5When performing the analytical operation of the DepthwiseConv2D operator, if the attribute depth_multiplier is 0, it wil...
CVE-2021-33650HIGH7.5When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three,...
CVE-2021-33649HIGH7.5When performing the inference shape operation of the Transpose operator, if the value in the perm element is greater tha...
CVE-2021-33648HIGH7.5When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operator...
CVE-2021-33647HIGH7.5When performing the inference shape operation of the Tile operator, if the input data type is not int or int32, it will ...
CVE-2021-40901HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating c...
CVE-2021-40900HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted in...
CVE-2021-40899HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloadi...
CVE-2021-40898HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying craft...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now