DE EN FR
hlukh.ch MàJ : 2026-02-25T09:01:16.562Z · week: 2021-W23

Alertes de sécurité

Sélectionnées à partir d'avis publics. Objectif : visibilité, contexte et export rapide — sans clickbait.

Alertes récentes
CVE-2021-31942
3D Viewer Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31942
MSRC 2026‑02‑21 Élevée
CVE-2021-31943
3D Viewer Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31943
MSRC 2026‑02‑21 Élevée
CVE-2021-32027
A flaw was found in postgresql in versions before 13.3 before 12.7 before 11.12 before 10.17 and before 9.6.22. While modifying certain SQL array values missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2026‑02‑21 · CVE-2021-32027
MSRC 2026‑02‑21 Élevée
CVE-2021-23017
A security issue in nginx resolver was identified which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite resulting in worker process crash or potential other impact.
2026‑02‑21 · CVE-2021-23017
MSRC 2026‑02‑21 Élevée
CVE-2021-32078
An Out-of-Bounds Read was discovered in arch/arm/mach-footbridge/personal-pci.c in the Linux kernel through 5.12.11 because of the lack of a check for a value that shouldn't be negative e.g. access to element -2 of an array aka CID-298a58e165e4.
2026‑02‑21 · CVE-2021-32078
MSRC 2026‑02‑21 Élevée
CVE-2021-3546
An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw occurs while processing the 'VIRTIO_GPU_CMD_GET_CAPSET' command from the guest. It could allow a privileged guest user to crash the QEMU process on the host resulting in a denial of service condition or potential code execution with the privileges of the QEMU process.
2026‑02‑21 · CVE-2021-3546
MSRC 2026‑02‑21 Élevée
CVE-2021-28210
An unlimited recursion in DxeCore in EDK II.
2026‑02‑21 · CVE-2021-28210
MSRC 2026‑02‑21 Élevée
CVE-2021-22901
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory libcurl might even call a function pointer in the object making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct
2026‑02‑21 · CVE-2021-22901
MSRC 2026‑02‑21 Élevée
CVE-2021-22222
Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file
2026‑02‑21 · CVE-2021-22222
MSRC 2026‑02‑21 Élevée
CVE-2021-28091
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
2026‑02‑21 · CVE-2021-28091
MSRC 2026‑02‑21 Élevée
CVE-2021-33560
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm and the window size is not chosen appropriately. This for example affects use of ElGamal in OpenPGP.
2026‑02‑21 · CVE-2021-33560
MSRC 2026‑02‑21 Élevée
CVE-2020-17541
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
2026‑02‑21 · CVE-2020-17541
MSRC 2026‑02‑21 Élevée
CVE-2018-10195
lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.
2026‑02‑21 · CVE-2018-10195
MSRC 2026‑02‑21 Élevée
CVE-2021-31985
Microsoft Defender Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31985
MSRC 2026‑02‑21 Élevée
CVE-2021-33739
Microsoft DWM Core Library Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-33739
MSRC 2026‑02‑21 Élevée
CVE-2021-33741
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-33741
MSRC 2026‑02‑21 Élevée
CVE-2021-31939
Microsoft Excel Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31939
MSRC 2026‑02‑21 Élevée
CVE-2021-31980
Microsoft Intune Management Extension Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31980
MSRC 2026‑02‑21 Élevée
CVE-2021-31940
Microsoft Office Graphics Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31940
MSRC 2026‑02‑21 Élevée
CVE-2021-31941
Microsoft Office Graphics Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31941
MSRC 2026‑02‑21 Élevée
CVE-2021-31949
Microsoft Outlook Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31949
MSRC 2026‑02‑21 Élevée
CVE-2021-26420
Microsoft SharePoint Server Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-26420
MSRC 2026‑02‑21 Élevée
CVE-2021-31963
Microsoft SharePoint Server Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31963
MSRC 2026‑02‑21 Élevée
CVE-2021-31966
Microsoft SharePoint Server Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31966
MSRC 2026‑02‑21 Élevée
CVE-2021-31964
Microsoft SharePoint Server Spoofing Vulnerability
2026‑02‑21 · CVE-2021-31964
MSRC 2026‑02‑21 Élevée
CVE-2021-31948
Microsoft SharePoint Server Spoofing Vulnerability
2026‑02‑21 · CVE-2021-31948
MSRC 2026‑02‑21 Élevée
CVE-2021-31950
Microsoft SharePoint Server Spoofing Vulnerability
2026‑02‑21 · CVE-2021-31950
MSRC 2026‑02‑21 Élevée
CVE-2021-31938
Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-31938
MSRC 2026‑02‑21 Élevée
CVE-2020-35452
mod_auth_digest possible stack overflow by one nul byte
2026‑02‑21 · CVE-2020-35452
MSRC 2026‑02‑21 Élevée
CVE-2020-13950
mod_proxy_http NULL pointer dereference
2026‑02‑21 · CVE-2020-13950
MSRC 2026‑02‑21 Élevée
CVE-2021-26690
mod_session NULL pointer dereference
2026‑02‑21 · CVE-2021-26690
MSRC 2026‑02‑21 Élevée
CVE-2021-31618
NULL pointer dereference on specially crafted HTTP/2 request
2026‑02‑21 · CVE-2021-31618
MSRC 2026‑02‑21 Élevée
CVE-2021-31945
Paint 3D Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31945
MSRC 2026‑02‑21 Élevée
CVE-2021-31946
Paint 3D Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31946
MSRC 2026‑02‑21 Élevée
CVE-2021-31983
Paint 3D Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31983
MSRC 2026‑02‑21 Élevée
CVE-2021-32690
Repository credentials passed to alternate domain
2026‑02‑21 · CVE-2021-32690
MSRC 2026‑02‑21 Élevée
CVE-2021-31974
Server for NFS Denial of Service Vulnerability
2026‑02‑21 · CVE-2021-31974
MSRC 2026‑02‑21 Élevée
CVE-2021-31975
Server for NFS Information Disclosure Vulnerability
2026‑02‑21 · CVE-2021-31975
MSRC 2026‑02‑21 Élevée
CVE-2021-31976
Server for NFS Information Disclosure Vulnerability
2026‑02‑21 · CVE-2021-31976
MSRC 2026‑02‑21 Élevée
CVE-2021-31967
VP9 Video Extensions Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-31967
MSRC 2026‑02‑21 Élevée
CVE-2021-31969
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-31969
MSRC 2026‑02‑21 Élevée
CVE-2021-31954
Windows Common Log File System Driver Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-31954
MSRC 2026‑02‑21 Élevée
CVE-2021-31953
Windows Filter Manager Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-31953
MSRC 2026‑02‑21 Élevée
CVE-2021-31973
Windows GPSVC Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-31973
MSRC 2026‑02‑21 Élevée
CVE-2021-31977
Windows Hyper-V Denial of Service Vulnerability
2026‑02‑21 · CVE-2021-31977
MSRC 2026‑02‑21 Élevée
CVE-2021-31951
Windows Kernel Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-31951
MSRC 2026‑02‑21 Élevée
CVE-2021-31952
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-31952
MSRC 2026‑02‑21 Élevée
CVE-2021-33742
Windows MSHTML Platform Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2021-33742
MSRC 2026‑02‑21 Élevée
CVE-2021-31956
Windows NTFS Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-31956
MSRC 2026‑02‑21 Élevée
CVE-2021-31958
Windows NTLM Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2021-31958
MSRC 2026‑02‑21 Élevée
Page 1