Vulnerabilities > Debian > High

DATE CVE VULNERABILITY TITLE RISK
2021-04-26 CVE-2021-21213 Use After Free vulnerability in multiple products
Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-416
8.8
2021-04-26 CVE-2021-21225 Out-of-bounds Write vulnerability in multiple products
Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-787
8.8
2021-04-26 CVE-2021-21224 Type Confusion vulnerability in multiple products
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-843
8.8
2021-04-26 CVE-2021-21207 Use After Free vulnerability in multiple products
Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
local
low complexity
google debian fedoraproject CWE-416
8.6
2021-04-26 CVE-2021-21205 Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google debian fedoraproject
8.1
2021-04-26 CVE-2021-3472 A flaw was found in xorg-x11-server in versions before 1.20.11.
local
low complexity
x-org fedoraproject debian redhat
7.8
2021-04-26 CVE-2020-15078 Missing Authentication for Critical Function vulnerability in multiple products
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
network
low complexity
openvpn fedoraproject canonical debian CWE-306
7.5
2021-04-24 CVE-2021-31598 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in libezxml.a in ezXML 0.8.6.
network
low complexity
ezxml-project debian CWE-787
7.5
2021-04-23 CVE-2021-22204 Code Injection vulnerability in multiple products
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
7.8
2021-04-22 CVE-2021-23133 Race Condition vulnerability in multiple products
A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process.
7.0