DE EN FR
hlukh.ch MàJ : 2026-02-26T21:02:01.989Z · week: 2021-W10

Alertes de sécurité

Sélectionnées à partir d'avis publics. Objectif : visibilité, contexte et export rapide — sans clickbait.

Alertes récentes
CVE-2020-8277
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2020-8277
MSRC 2026‑02‑26 Élevée
CVE-2020-8032
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2020-8032
MSRC 2026‑02‑26 Élevée
CVE-2021-27803
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2021-27803
MSRC 2026‑02‑26 Élevée
CVE-2021-21309
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑26 · CVE-2021-21309
MSRC 2026‑02‑26 Élevée
CVE-2020-35492
A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example by convincing a user to open a file in an application using cairo or if an application uses cairo on untrusted input) to cause a stack buffer overflow -&gt; out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality integrity as well as system availability.
2026‑02‑26 · CVE-2020-35492
MSRC 2026‑02‑26 Élevée
CVE-2020-14372
A flaw was found in grub2 in versions prior to 2.06 where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is further loaded and executed by the kernel defeating its Secure Boot lockdown and allowing the attacker to load unsigned code. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2020-14372
MSRC 2026‑02‑26 Élevée
CVE-2020-25647
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of the Secure Boot mechanism. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2020-25647
MSRC 2026‑02‑26 Élevée
CVE-2021-20233
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2021-20233
MSRC 2026‑02‑26 Élevée
CVE-2020-27779
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2020-27779
MSRC 2026‑02‑26 Élevée
CVE-2020-25632
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑26 · CVE-2020-25632
MSRC 2026‑02‑26 Élevée
CVE-2020-27827
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
2026‑02‑26 · CVE-2020-27827
MSRC 2026‑02‑26 Élevée
CVE-2021-20271
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package whose signature header was modified to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity confidentiality and system availability.
2026‑02‑26 · CVE-2021-20271
MSRC 2026‑02‑26 Élevée
CVE-2020-35524
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.
2026‑02‑26 · CVE-2020-35524
MSRC 2026‑02‑26 Élevée
CVE-2021-27928
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37 10.3 before 10.3.28 10.4 before 10.4.18 and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.
2026‑02‑26 · CVE-2021-27928
MSRC 2026‑02‑26 Élevée
CVE-2021-20270
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file as demonstrated by input that only contains the "exception" keyword.
2026‑02‑26 · CVE-2021-20270
MSRC 2026‑02‑26 Élevée
CVE-2020-35523
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.
2026‑02‑26 · CVE-2020-35523
MSRC 2026‑02‑26 Élevée
CVE-2021-28361
An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected) the iSCSI target can crash with a NULL pointer dereference.
2026‑02‑26 · CVE-2021-28361
MSRC 2026‑02‑26 Élevée
CVE-2021-29266
An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v-&gt;config_ctx has an invalid value upon re-opening a character device aka CID-f6bbf0010ba0.
2026‑02‑26 · CVE-2021-29266
MSRC 2026‑02‑26 Élevée
CVE-2021-27365
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI and has a length up to the maximum length of a Netlink message.
2026‑02‑26 · CVE-2021-27365
MSRC 2026‑02‑26 Élevée
CVE-2021-27364
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
2026‑02‑26 · CVE-2021-27364
MSRC 2026‑02‑26 Élevée
CVE-2021-28375
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.
2026‑02‑26 · CVE-2021-28375
MSRC 2026‑02‑26 Élevée
CVE-2021-28952
An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)
2026‑02‑26 · CVE-2021-28952
MSRC 2026‑02‑26 Élevée
CVE-2021-20268
An out-of-bounds access flaw was found in the Linux kernel's implementation of the eBPF code verifier in the way a user running the eBPF script calls dev_map_init_map or sock_map_alloc. This flaw allows a local user to crash the system or possibly escalate their privileges. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.
2026‑02‑26 · CVE-2021-20268
MSRC 2026‑02‑26 Élevée
CVE-2021-26890
Application Virtualization Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-26890
MSRC 2026‑02‑26 Élevée
CVE-2021-28831
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer with a resultant invalid free or segmentation fault via malformed gzip data.
2026‑02‑26 · CVE-2021-28831
MSRC 2026‑02‑26 Élevée
CVE-2021-24095
DirectX Elevation of Privilege Vulnerability
2026‑02‑26 · CVE-2021-24095
MSRC 2026‑02‑26 Élevée
CVE-2021-27918
encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode DecodeElement or Skip method.
2026‑02‑26 · CVE-2021-27918
MSRC 2026‑02‑26 Élevée
CVE-2021-21300
Git for Visual Studio Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-21300
MSRC 2026‑02‑26 Élevée
CVE-2021-24089
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-24089
MSRC 2026‑02‑26 Élevée
CVE-2021-24110
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-24110
MSRC 2026‑02‑26 Élevée
CVE-2021-26902
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-26902
MSRC 2026‑02‑26 Élevée
CVE-2021-27047
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27047
MSRC 2026‑02‑26 Élevée
CVE-2021-27048
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27048
MSRC 2026‑02‑26 Élevée
CVE-2021-27049
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27049
MSRC 2026‑02‑26 Élevée
CVE-2021-27050
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27050
MSRC 2026‑02‑26 Élevée
CVE-2021-27051
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27051
MSRC 2026‑02‑26 Élevée
CVE-2021-27061
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27061
MSRC 2026‑02‑26 Élevée
CVE-2021-27062
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27062
MSRC 2026‑02‑26 Élevée
CVE-2021-27291
In pygments 1.1+ fixed in 2.7.4 the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input an attacker can cause a denial of service.
2026‑02‑26 · CVE-2021-27291
MSRC 2026‑02‑26 Élevée
CVE-2021-26411
Internet Explorer Memory Corruption Vulnerability
2026‑02‑26 · CVE-2021-26411
MSRC 2026‑02‑26 Élevée
CVE-2021-27085
Internet Explorer Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27085
MSRC 2026‑02‑26 Élevée
CVE-2021-3444
Linux kernel bpf verifier incorrect mod32 truncation
2026‑02‑26 · CVE-2021-3444
MSRC 2026‑02‑26 Élevée
CVE-2021-27053
Microsoft Excel Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27053
MSRC 2026‑02‑26 Élevée
CVE-2021-27054
Microsoft Excel Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27054
MSRC 2026‑02‑26 Élevée
CVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-26857
MSRC 2026‑02‑26 Élevée
CVE-2021-26858
Microsoft Exchange Server Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-26858
MSRC 2026‑02‑26 Élevée
CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27065
MSRC 2026‑02‑26 Élevée
CVE-2021-27058
Microsoft Office ClickToRun Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27058
MSRC 2026‑02‑26 Élevée
CVE-2021-24108
Microsoft Office Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-24108
MSRC 2026‑02‑26 Élevée
CVE-2021-27057
Microsoft Office Remote Code Execution Vulnerability
2026‑02‑26 · CVE-2021-27057
MSRC 2026‑02‑26 Élevée
Page 1