ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-44506
+1 in the same advisory: …44505
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base).

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.

NVD description · AI analysis pending
7.52%
  • yottadb gt.m
CVE-2021-44486
An issue was discovered in YottaDB through r1.32 and V7.0-000.

An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c in order to gain control of the flow of execution.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • fisglobal gt.m
  • fisglobal yottadb
CVE-2021-27377
An issue was discovered in the yottadb crate before 1.2.0 for Rust.

An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_next_st and ydb_subscript_prev_st have a use-after-free.

NVD description · AI analysis pending
9.81% PoC
  • yottadb yottadb