Log

CVE-2021-1817 created at 25 Jul 2021 12:14:27
Severity
+ Medium
Remote
+ Remote
Type
+ Arbitrary code execution
Description
+ A security issue has been found in WebKitGTK and WPE WebKit before 2.30.0. Processing maliciously crafted web content may lead to arbitrary code execution.
References
+ https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-1817
Notes
AVG-2039 edited at 23 Jul 2021 12:26:59
Affected
- 3.1.1-1
+ 3.1.2-1
AVG-1667 edited at 23 Jul 2021 10:41:26
Affected
- 4.15-1
+ 4.16-1
CVE-2021-28116 edited at 23 Jul 2021 10:41:20
Description
- Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
+ Squid, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
References
https://www.zerodayinitiative.com/advisories/ZDI-21-157/
https://github.com/squid-cache/squid/security/advisories/GHSA-rgf3-9v3p-qp82
+ https://bugs.squid-cache.org/show_bug.cgi?id=5131
AVG-1880 edited at 23 Jul 2021 10:40:27
Affected
- 5.13.4.zen1-1
+ 5.13.4.zen2-1
AVG-1879 edited at 23 Jul 2021 10:40:20
Affected
- 5.13.4.arch1-1
+ 5.13.4.arch2-1
AVG-1594 edited at 23 Jul 2021 10:40:09
Affected
- 5.13.4.arch1-1
+ 5.13.4.arch2-1
AVG-2207 edited at 23 Jul 2021 10:39:50
Severity
- Unknown
+ Low
CVE-2020-25691 edited at 23 Jul 2021 10:39:50
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ A security issue was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1893725
Notes
AVG-2207 created at 23 Jul 2021 10:39:14
Packages
+ darkhttpd
Issues
+ CVE-2020-25691
Status
+ Vulnerable
Severity
+ Unknown
Affected
+ 1.13-1
Fixed
Ticket
Advisory qualified
+ Yes
References
Notes
CVE-2020-25691 created at 23 Jul 2021 10:39:14
CVE-2021-3246 edited at 23 Jul 2021 10:37:29
Description
- A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
+ A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile before version 1.1.0 allows attackers to execute arbitrary code via a crafted WAV file.
References
https://github.com/libsndfile/libsndfile/issues/687
+ https://oss-fuzz.com/testcase-detail/5696502087024640
+ https://github.com/libsndfile/libsndfile/pull/707
+ https://github.com/libsndfile/libsndfile/commit/9e0e55f8bfa60bddca083ff85699f855c91c42e7