Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2021
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.
CVSS Score
4.5
EPSS Score
0.001
Published
2021-03-26
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
CVSS Score
5.3
EPSS Score
0.004
Published
2021-03-26
MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions affected: Mule 4.1.x and 4.2.x runtime released before February 2, 2021.
CVSS Score
9.8
EPSS Score
0.023
Published
2021-03-26
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.
CVSS Score
9.8
EPSS Score
0.004
Published
2021-03-26
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021.
CVSS Score
9.8
EPSS Score
0.004
Published
2021-03-26
Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-03-26
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.
CVSS Score
3.3
EPSS Score
0.001
Published
2021-03-26
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.
CVSS Score
6.3
EPSS Score
0.002
Published
2021-03-26
A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.
CVSS Score
5.5
EPSS Score
0.002
Published
2021-03-26
SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
CVSS Score
4.8
EPSS Score
0.01
Published
2021-03-26


Contact Us

Shodan ® - All rights reserved