CVE-2021-41591

CRITICAL Year: 2021
CVSS v3 Score
9.4
Critical
CVSS v2 Score
7.5
High

Vulnerability Description

ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure.

CVSS:9.4(Critical)

Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.

CVSS:9.1(Critical)

In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both ...

CVSS:9.1(Critical)

An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.

CVSS:9.1(Critical)

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system term...

CVSS:9.1(Critical)

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must ...

CVSS:9.8(Critical)

A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deall...