CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-42687

    Last Modified: 21 Nov 2024

    A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42686

    Last Modified: 21 Nov 2024

    An Integer Overflow exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B in the Accops HyWorks Windows Client prior to v 3.2.8.200 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42685

    Last Modified: 21 Nov 2024

    An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 . The IOCTL Handler 0x22005B in the Accops HyWorks DVM Tools prior to v3.3.1.105 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42683

    Last Modified: 21 Nov 2024

    A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42682

    Last Modified: 21 Nov 2024

    An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 .The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42681

    Last Modified: 21 Nov 2024

    A Buffer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105. The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43638

    Last Modified: 21 Nov 2024

    Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43637

    Last Modified: 21 Nov 2024

    Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43006

    Last Modified: 21 Nov 2024

    AmZetta Amzetta zPortal DVM Tools is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal DVM Tools <= v3.3.148.148 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43003

    Last Modified: 21 Nov 2024

    Amzetta zPortal Windows zClient is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal Windows zClient <= v3.2.8180.148 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43002

    Last Modified: 21 Nov 2024

    Amzetta zPortal DVM Tools is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal DVM Tools <= v3.3.148.148 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43000

    Last Modified: 21 Nov 2024

    Amzetta zPortal Windows zClient is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal Windows zClient <= v3.2.8180.148 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42996

    Last Modified: 21 Nov 2024

    Donglify is affected by Integer Overflow. IOCTL Handler 0x22001B in the Donglify above 1.0.12309 below 1.7.14110 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42994

    Last Modified: 21 Nov 2024

    Donglify is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Donglify above 1.0.12309 below 1.7.14110 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42993

    Last Modified: 21 Nov 2024

    FlexiHub For Windows is affected by Integer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42990

    Last Modified: 21 Nov 2024

    FlexiHub For Windows is affected by Buffer Overflow. IOCTL Handler 0x22001B in the FlexiHub For Windows above 2.0.4340 below 5.3.14268 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42988

    Last Modified: 21 Nov 2024

    Eltima USB Network Gate is affected by Buffer Overflow. IOCTL Handler 0x22001B in the USB Network Gate above 7.0.1370 below 9.2.2420 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42987

    Last Modified: 21 Nov 2024

    Eltima USB Network Gate is affected by Integer Overflow. IOCTL Handler 0x22001B in the USB Network Gate above 7.0.1370 below 9.2.2420 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42986

    Last Modified: 21 Nov 2024

    NoMachine Enterprise Client is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Client above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42983

    Last Modified: 21 Nov 2024

    NoMachine Enterprise Client is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Client above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42980

    Last Modified: 21 Nov 2024

    NoMachine Cloud Server is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42979

    Last Modified: 21 Nov 2024

    NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42977

    Last Modified: 21 Nov 2024

    NoMachine Enterprise Desktop is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42976

    Last Modified: 21 Nov 2024

    NoMachine Enterprise Desktop is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42973

    Last Modified: 21 Nov 2024

    NoMachine Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-42972

    Last Modified: 21 Nov 2024

    NoMachine Server is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-40288

    Last Modified: 21 Nov 2024

    A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in TP-Link AX10v1 before V1_211014, allows a remote unauthenticated attacker to disconnect an already connected wireless client via sending with a wireless adapter specific spoofed authentication frames

    Published: 7 Dec 2021
    9.8
    Critical

    CVE-2021-24041

    Last Modified: 21 Nov 2024

    A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a user sent a malicious image.

    Published: 7 Dec 2021
    6.8
    Medium

    CVE-2021-37940

    Last Modified: 21 Nov 2024

    An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server integration. Using this vulnerability, a malicious Workplace Search admin could use the GHES integration to view hosts that might not be publicly accessible.

    Published: 7 Dec 2021
    9.8
    Critical

    CVE-2021-40859

    Last Modified: 21 Nov 2024

    Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.

    Published: 7 Dec 2021
    9.8
    Critical

    CVE-2021-41716

    Last Modified: 21 Nov 2024

    Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

    Published: 7 Dec 2021
    8.8
    High

    CVE-2020-12140

    Last Modified: 21 Nov 2024

    A buffer overflow in os/net/mac/ble/ble-l2cap.c in the BLE stack in Contiki-NG 4.4 and earlier allows an attacker to execute arbitrary code via malicious L2CAP frames.

    Published: 7 Dec 2021
    8.8
    High

    CVE-2021-43176

    Last Modified: 21 Nov 2024

    The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 takes a user-supplied “action” parameter and appends a .php file extension to locate and load the correct PHP file to implement the API call. Vulnerable versions of GOautodial do not sanitize the user input that specifies the action. This permits an attacker to execute any PHP source file with a .php extension that is present on the disk and readable by the GOautodial web server process. Combined with CVE-2021-43175, it is possible for the attacker to do this without valid credentials. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-43175

    Last Modified: 21 Nov 2024

    The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOautodial validate the username and password incorrectly, allowing the caller to specify any values for these parameters and successfully authenticate. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-43805

    Last Modified: 21 Nov 2024

    Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular expression used to validate a guest order's email was subject to exponential backtracking through a fragment like `a.a.` Versions 3.1.4, 3.0.4, and 2.11.13 have been patched to use a different regular expression. The maintainers added a check for email addresses that are no longer valid that will print information about any affected orders that exist. If a prompt upgrade is not an option, a workaround is available. It is possible to edit the file `config/application.rb` manually (with code provided by the maintainers in the GitHub Security Advisory) to check email validity.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-43789

    Last Modified: 21 Nov 2024

    PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with `orderBy` and `sortOrder` parameters. The problem is fixed in version 1.7.8.2.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-37100

    Last Modified: 21 Nov 2024

    There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed.

    Published: 7 Dec 2021
    9.1
    Critical

    CVE-2021-37099

    Last Modified: 21 Nov 2024

    There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete any file.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-37096

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed.

    Published: 7 Dec 2021
    9.8
    Critical

    CVE-2021-37095

    Last Modified: 21 Nov 2024

    There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remote denial of service and potential remote code execution.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-37094

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-37091

    Last Modified: 21 Nov 2024

    There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to confidentiality affected.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-37090

    Last Modified: 21 Nov 2024

    There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to process crash.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-37089

    Last Modified: 21 Nov 2024

    There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to kernel restart.

    Published: 7 Dec 2021
    9.1
    Critical

    CVE-2021-37088

    Last Modified: 21 Nov 2024

    There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can write any content to any file.

    Published: 7 Dec 2021
    9.1
    Critical

    CVE-2021-37087

    Last Modified: 21 Nov 2024

    There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can create arbitrary file.

    Published: 7 Dec 2021
    8.6
    High

    CVE-2021-37086

    Last Modified: 21 Nov 2024

    There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read synchronization files of other applications across the UID sandbox.

    Published: 7 Dec 2021
    5.9
    Medium

    CVE-2021-37085

    Last Modified: 21 Nov 2024

    There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.

    Published: 7 Dec 2021
    9.8
    Critical

    CVE-2021-37084

    Last Modified: 21 Nov 2024

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious invoking other functions of the Smart Assistant through text messages.

    Published: 7 Dec 2021
    7.5
    High

    CVE-2021-37083

    Last Modified: 21 Nov 2024

    There is a NULL Pointer Dereference vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Denial of Service Attacks.

    Published: 7 Dec 2021