CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-41121

    Last Modified: 21 Nov 2024

    Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions when performing a function call inside a literal struct, there is a memory corruption issue that occurs because of an incorrect pointer to the the top of the stack. This issue has been resolved in version 0.3.0.

    Published: 6 Oct 2021
    7.5
    High

    CVE-2021-38925

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210171.

    Published: 6 Oct 2021
    6
    Medium

    CVE-2021-25490

    Last Modified: 21 Nov 2024

    A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.

    Published: 6 Oct 2021
    9.8
    Critical

    CVE-2021-29903

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 207506.

    Published: 6 Oct 2021
    5.4
    Medium

    CVE-2021-29855

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205684.

    Published: 6 Oct 2021
    8.8
    High

    CVE-2021-29837

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204913.

    Published: 6 Oct 2021
    5.4
    Medium

    CVE-2021-29836

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204912.

    Published: 6 Oct 2021
    3.3
    Low

    CVE-2021-25489

    Last Modified: 30 Oct 2025

    Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

    Published: 6 Oct 2021
    9.8
    Critical

    CVE-2021-29798

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734.

    Published: 6 Oct 2021
    5.4
    Medium

    CVE-2021-29764

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 202268.

    Published: 6 Oct 2021
    4.3
    Medium

    CVE-2021-29761

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information from the dashboard that they should not have access to. IBM X-Force ID: 202265.

    Published: 6 Oct 2021
    4.3
    Medium

    CVE-2021-29760

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unauthorized files through the dashboard user interface. IBM X-Force ID: 202213.

    Published: 6 Oct 2021
    5.5
    Medium

    CVE-2021-25488

    Last Modified: 21 Nov 2024

    Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.

    Published: 6 Oct 2021
    4.3
    Medium

    CVE-2021-29758

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X-Force ID: 202169.

    Published: 6 Oct 2021
    7.3
    High

    CVE-2021-25487

    Last Modified: 30 Oct 2025

    Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

    Published: 6 Oct 2021
    2.5
    Low

    CVE-2021-25486

    Last Modified: 21 Nov 2024

    Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log.

    Published: 6 Oct 2021
    7.5
    High

    CVE-2021-25485

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.

    Published: 6 Oct 2021
    4
    Medium

    CVE-2021-25484

    Last Modified: 21 Nov 2024

    Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.

    Published: 6 Oct 2021
    4
    Medium

    CVE-2021-25483

    Last Modified: 21 Nov 2024

    Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.

    Published: 6 Oct 2021
    5.9
    Medium

    CVE-2021-25482

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite some CMFA framework information.

    Published: 6 Oct 2021
    6.4
    Medium

    CVE-2021-25481

    Last Modified: 21 Nov 2024

    An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP Memory.

    Published: 6 Oct 2021
    4.4
    Medium

    CVE-2021-25480

    Last Modified: 21 Nov 2024

    A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network connection.

    Published: 6 Oct 2021
    7.2
    High

    CVE-2021-25479

    Last Modified: 21 Nov 2024

    A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

    Published: 6 Oct 2021
    7.2
    High

    CVE-2021-25478

    Last Modified: 21 Nov 2024

    A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

    Published: 6 Oct 2021
    4.4
    Medium

    CVE-2021-25477

    Last Modified: 21 Nov 2024

    An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.

    Published: 6 Oct 2021
    4.1
    Medium

    CVE-2021-25476

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.

    Published: 6 Oct 2021
    3.9
    Low

    CVE-2021-25475

    Last Modified: 21 Nov 2024

    A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

    Published: 6 Oct 2021
    4.4
    Medium

    CVE-2021-25474

    Last Modified: 21 Nov 2024

    Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.

    Published: 6 Oct 2021
    4.4
    Medium

    CVE-2021-25473

    Last Modified: 21 Nov 2024

    Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.

    Published: 6 Oct 2021
    4
    Medium

    CVE-2021-25472

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.

    Published: 6 Oct 2021
    3.7
    Low

    CVE-2021-25471

    Last Modified: 21 Nov 2024

    A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.

    Published: 6 Oct 2021
    7.9
    High

    CVE-2021-25470

    Last Modified: 21 Nov 2024

    An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

    Published: 6 Oct 2021
    6
    Medium

    CVE-2021-25469

    Last Modified: 21 Nov 2024

    A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code execution.

    Published: 6 Oct 2021
    4.4
    Medium

    CVE-2021-25468

    Last Modified: 21 Nov 2024

    A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory address.

    Published: 6 Oct 2021
    5.3
    Medium

    CVE-2021-25467

    Last Modified: 21 Nov 2024

    Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows privilege escalation to Root by hijacking loaded library.

    Published: 6 Oct 2021
    6.5
    Medium

    CVE-2021-39351

    Last Modified: 14 Feb 2025

    The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2.

    Published: 6 Oct 2021
    6.1
    Medium

    CVE-2021-39350

    Last Modified: 14 Feb 2025

    The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

    Published: 6 Oct 2021
    5.5
    Medium

    CVE-2021-0680

    Last Modified: 21 Nov 2024

    In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-192535676

    Published: 6 Oct 2021
    5.5
    Medium

    CVE-2021-0681

    Last Modified: 21 Nov 2024

    In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-192535337

    Published: 6 Oct 2021
    7.8
    High

    CVE-2021-0685

    Last Modified: 21 Nov 2024

    In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-191055353

    Published: 6 Oct 2021
    5.5
    Medium

    CVE-2021-0689

    Last Modified: 21 Nov 2024

    In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-190188264

    Published: 6 Oct 2021
    7.8
    High

    CVE-2021-0635

    Last Modified: 21 Nov 2024

    When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss of user rights.Product: Androidversion:Android-10Android ID: A-189402477

    Published: 6 Oct 2021
    7.8
    High

    CVE-2021-0636

    Last Modified: 21 Nov 2024

    When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video cannot be played, and the log is found to be crashed. This problem may lead to hacker malicious code attacks, resulting in the loss of user rights.Product: Androidversion: Android-10Android ID: A-189392423

    Published: 6 Oct 2021
    5
    Medium

    CVE-2021-0687

    Last Modified: 21 Nov 2024

    In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-188913943

    Published: 6 Oct 2021
    6.7
    Medium

    CVE-2021-0691

    Last Modified: 21 Nov 2024

    In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in other processes due to an overly-permissive SELinux policy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-188554048

    Published: 6 Oct 2021
    7.8
    High

    CVE-2021-0683

    Last Modified: 21 Nov 2024

    In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-185398942

    Published: 6 Oct 2021
    5.5
    Medium

    CVE-2021-0693

    Last Modified: 21 Nov 2024

    In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-184046948

    Published: 6 Oct 2021
    5.5
    Medium

    CVE-2021-0695

    Last Modified: 21 Nov 2024

    In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-184018316References: Upstream kernel

    Published: 6 Oct 2021
    6.5
    Medium

    CVE-2021-0690

    Last Modified: 21 Nov 2024

    In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-182152757

    Published: 6 Oct 2021
    5.5
    Medium

    CVE-2021-0644

    Last Modified: 21 Nov 2024

    In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-181053462

    Published: 6 Oct 2021