Search Results (92847 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-42255 1 Blueplanet-works 1 Appguard 2024-11-21 7.8 High
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
CVE-2021-42254 1 Beyondtrust 1 Privilege Management For Windows 2024-11-21 7.8 High
BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2021-42252 2 Linux, Netapp 20 Linux Kernel, Cloud Backup, H300e and 17 more 2024-11-21 7.8 High
An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.
CVE-2021-42228 1 Kindsoft 1 Kindeditor 2024-11-21 8.8 High
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
CVE-2021-42219 1 Ethereum 1 Go Ethereum 2024-11-21 7.5 High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go.
CVE-2021-42218 1 Rice 1 Open Motion Planning Library 2024-11-21 7.5 High
OMPL v1.5.2 contains a memory leak in VFRRT.cpp
CVE-2021-42204 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause code execution.
CVE-2021-42203 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.
CVE-2021-42201 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution.
CVE-2021-42199 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.
CVE-2021-42197 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allows an attacker to cause code execution.
CVE-2021-42195 1 Swftools 1 Swftools 2024-11-21 7.8 High
An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function handleEditText() located in swfdump.c. It allows an attacker to cause code Execution.
CVE-2021-42194 1 Eyoucms 1 Eyoucms 2024-11-21 7.2 High
The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability.
CVE-2021-42192 1 Konga Project 1 Konga 2024-11-21 8.8 High
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.
CVE-2021-42183 1 Masacms 1 Masacms 2024-11-21 7.5 High
MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.
CVE-2021-42171 1 Tribalsystems 1 Zenario 2024-11-21 7.2 High
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.
CVE-2021-42165 1 Mitrastar 2 Gpt-2541gnac-n1, Gpt-2541gnac-n1 Firmware 2024-11-21 8.8 High
MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".
CVE-2021-42138 1 Thalesgroup 1 Safenet Windows Logon Agent 2024-11-21 7.2 High
A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine.
CVE-2021-42135 1 Hashicorp 1 Vault 2024-11-21 8.1 High
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.
CVE-2021-42133 1 Ivanti 1 Avalanche 2024-11-21 8.1 High
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.