CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-45693

    Last Modified: 21 Nov 2024

    An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory locations.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45694

    Last Modified: 21 Nov 2024

    An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45695

    Last Modified: 21 Nov 2024

    An issue was discovered in the mopa crate through 2021-06-01 for Rust. It incorrectly relies on Trait memory layout, possibly leading to future occurrences of arbitrary code execution or ASLR bypass.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45696

    Last Modified: 21 Nov 2024

    An issue was discovered in the sha2 crate 0.9.7 before 0.9.8 for Rust. Hashes of long messages may be incorrect when the AVX2-accelerated backend is used.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45697

    Last Modified: 21 Nov 2024

    An issue was discovered in the molecule crate before 0.7.2 for Rust. A FixVec partial read has an incorrect result.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45698

    Last Modified: 21 Nov 2024

    An issue was discovered in the ckb crate before 0.40.0 for Rust. A get_block_template RPC call may fail in situations where it is supposed to select a Nervos CKB blockchain transaction with a higher fee rate than another transaction.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45699

    Last Modified: 21 Nov 2024

    An issue was discovered in the ckb crate before 0.40.0 for Rust. Remote attackers may be able to conduct a 51% attack against the Nervos CKB blockchain by triggering an inability to allocate memory for the misbehavior HashMap.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45700

    Last Modified: 21 Nov 2024

    An issue was discovered in the ckb crate before 0.40.0 for Rust. Attackers can cause a denial of service (Nervos CKB blockchain node crash) via a dead call that is used as a DepGroup.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45701

    Last Modified: 21 Nov 2024

    An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A patch operation may result in a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45702

    Last Modified: 21 Nov 2024

    An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-free.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45703

    Last Modified: 21 Nov 2024

    An issue was discovered in the tectonic_xdv crate before 0.1.12 for Rust. XdvParser::<T>::process may read from uninitialized memory locations.

    Published: 26 Dec 2021
    8.1
    High

    CVE-2021-45704

    Last Modified: 21 Nov 2024

    An issue was discovered in the metrics-util crate before 0.7.0 for Rust. There is a data race and memory corruption because AtomicBucket<T> unconditionally implements the Send and Sync traits.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45705

    Last Modified: 21 Nov 2024

    An issue was discovered in the nanorand crate before 0.6.1 for Rust. There can be multiple mutable references to the same object because the TlsWyRand Deref implementation dereferences a raw pointer.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45706

    Last Modified: 21 Nov 2024

    An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust. Dropped memory is not zeroed out for an enum.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45707

    Last Modified: 21 Nov 2024

    An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45708

    Last Modified: 21 Nov 2024

    An issue was discovered in the abomonation crate through 2021-10-17 for Rust. Because transmute operations are insufficiently constrained, there can be an information leak or ASLR bypass.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45709

    Last Modified: 21 Nov 2024

    An issue was discovered in the crypto2 crate through 2021-10-08 for Rust. During Chacha20 encryption and decryption, an unaligned read of a u32 may occur.

    Published: 26 Dec 2021
    8.1
    High

    CVE-2021-45710

    Last Modified: 21 Nov 2024

    An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45711

    Last Modified: 21 Nov 2024

    An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied by a remote attacker, has a second character greater than 0x7f.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45712

    Last Modified: 21 Nov 2024

    An issue was discovered in the rust-embed crate before 6.3.0 for Rust. A ../ directory traversal can sometimes occur in debug mode.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45713

    Last Modified: 21 Nov 2024

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_scalar_function has a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45714

    Last Modified: 21 Nov 2024

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_aggregate_function has a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45715

    Last Modified: 21 Nov 2024

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_window_function has a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45716

    Last Modified: 21 Nov 2024

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_collation has a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45717

    Last Modified: 21 Nov 2024

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. commit_hook has a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45718

    Last Modified: 21 Nov 2024

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. rollback_hook has a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45719

    Last Modified: 21 Nov 2024

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. update_hook has a use-after-free.

    Published: 26 Dec 2021
    7.5
    High

    CVE-2021-45720

    Last Modified: 21 Nov 2024

    An issue was discovered in the lru crate before 0.7.1 for Rust. The iterators have a use-after-free, as demonstrated by an access after a pop operation.

    Published: 26 Dec 2021
    9.8
    Critical

    CVE-2021-45686

    Last Modified: 21 Nov 2024

    An issue was discovered in the csv-sniffer crate through 2021-01-05 for Rust. preamble_skipcount may read from uninitialized memory locations.

    Published: 26 Dec 2021
    6.1
    Medium

    CVE-2021-44598

    Last Modified: 21 Nov 2024

    Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then can store information by injecting the admin account on this system.

    Published: 26 Dec 2021
    8.8
    High

    CVE-2021-4168

    Last Modified: 21 Nov 2024

    showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 26 Dec 2021
    6.1
    Medium

    CVE-2021-4169

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 26 Dec 2021
    8.1
    High

    CVE-2021-44078

    Last Modified: 21 Nov 2024

    An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5. It allows local attackers to escape the sandbox. An attacker must first obtain the ability to execute crafted code in the target sandbox in order to exploit this vulnerability. The specific flaw exists within the virtual memory manager. The issue results from the faulty comparison of GVA and GPA while calling uc_mem_map_ptr to free part of a claimed memory block. An attacker can leverage this vulnerability to escape the sandbox and execute arbitrary code on the host machine.

    Published: 26 Dec 2021
    7.6
    High

    CVE-2021-45493

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.

    Published: 26 Dec 2021
    8.4
    High

    CVE-2021-45494

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.

    Published: 26 Dec 2021
    6.5
    Medium

    CVE-2021-45495

    Last Modified: 21 Nov 2024

    NETGEAR D7000 devices before 1.0.1.68 are affected by authentication bypass.

    Published: 26 Dec 2021
    9.1
    Critical

    CVE-2021-45496

    Last Modified: 21 Nov 2024

    NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.

    Published: 26 Dec 2021
    9.4
    Critical

    CVE-2021-45497

    Last Modified: 21 Nov 2024

    NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.

    Published: 26 Dec 2021
    6.5
    Medium

    CVE-2021-45498

    Last Modified: 21 Nov 2024

    NETGEAR R6700v2 devices before 1.2.0.88 are affected by authentication bypass.

    Published: 26 Dec 2021
    8.2
    High

    CVE-2021-45499

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects R6900P before 1.3.3.140, R7000P before 1.3.3.140, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.

    Published: 26 Dec 2021
    9.6
    Critical

    CVE-2021-45500

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects R7000P before 1.3.3.140 and R8000 before 1.0.4.68.

    Published: 26 Dec 2021
    9.4
    Critical

    CVE-2021-45501

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects AC2400 before 1.1.0.84, AC2600 before 1.1.0.84, D7000 before 1.0.1.82, R6020 before 1.0.0.52, R6080 before 1.0.0.52, R6120 before 1.0.0.80, R6220 before 1.1.0.110, R6230 before 1.1.0.110, R6260 before 1.1.0.84, R6330 before 1.1.0.84, R6350 before 1.1.0.84, R6700v2 before 1.1.0.84, R6800 before 1.1.0.84, R6850 before 1.1.0.84, R6900v2 before 1.1.0.84, R7200 before 1.1.0.84, R7350 before 1.1.0.84, R7400 before 1.1.0.84, and R7450 before 1.1.0.84.

    Published: 26 Dec 2021
    9.6
    Critical

    CVE-2021-45502

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

    Published: 26 Dec 2021
    9.6
    Critical

    CVE-2021-45503

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

    Published: 26 Dec 2021
    9.6
    Critical

    CVE-2021-45504

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBR852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

    Published: 26 Dec 2021
    9.6
    Critical

    CVE-2021-45505

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

    Published: 26 Dec 2021
    9.6
    Critical

    CVE-2021-45506

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

    Published: 26 Dec 2021
    9.6
    Critical

    CVE-2021-45507

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBW30 before 2.6.2.2, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, and RBS40V before 2.6.2.8.

    Published: 26 Dec 2021
    9.6
    Critical

    CVE-2021-45508

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, and RBR850 before 3.2.17.12.

    Published: 26 Dec 2021
    9.6
    Critical

    CVE-2021-45509

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

    Published: 26 Dec 2021