CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-21843

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. After validating the number of ranges, at [41] the library will multiply the count by the size of the GF_SubsegmentRangeInfo structure. On a 32-bit platform, this multiplication can result in an integer overflow causing the space of the array being allocated to be less than expected. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21846

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsz” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21845

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsc” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21847

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stts” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21851

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “csgp” decoder sample group description indices can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2021-31820

    Last Modified: 21 Nov 2024

    In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.

    Published: 18 Aug 2021
    9.8
    Critical

    CVE-2021-37608

    Last Modified: 21 Nov 2024

    Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12297.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2021-33580

    Last Modified: 21 Nov 2024

    User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. Since the attacker controls the string and the regex pattern he may cause a ReDoS by regex catastrophic backtracking on the server side. This problem has been fixed in Roller 6.0.2.

    Published: 18 Aug 2021
    6.1
    Medium

    CVE-2021-20792

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20775

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the data of Comment and Space without the viewing privilege.

    Published: 18 Aug 2021
    5.4
    Medium

    CVE-2021-20774

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20773

    Last Modified: 21 Nov 2024

    There is a vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.0, which may allow a remote authenticated attacker to delete the route information Workflow without the appropriate privilege.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20772

    Last Modified: 21 Nov 2024

    Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege.

    Published: 18 Aug 2021
    6.1
    Medium

    CVE-2021-20771

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2021
    5.4
    Medium

    CVE-2021-20770

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2021
    5.4
    Medium

    CVE-2021-20769

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20768

    Last Modified: 21 Nov 2024

    Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate privilege.

    Published: 18 Aug 2021
    5.4
    Medium

    CVE-2021-20767

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2021
    6.1
    Medium

    CVE-2021-20766

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2021
    6.1
    Medium

    CVE-2021-20765

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2021
    5.3
    Medium

    CVE-2021-20764

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20763

    Last Modified: 21 Nov 2024

    Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the appropriate privilege.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20762

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.

    Published: 18 Aug 2021
    2.7
    Low

    CVE-2021-20761

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20760

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the appropriate privilege.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20759

    Last Modified: 21 Nov 2024

    Operational restrictions bypass vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.

    Published: 18 Aug 2021
    8
    High

    CVE-2021-20758

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitrary operation via unspecified vectors.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20757

    Last Modified: 21 Nov 2024

    Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20756

    Last Modified: 21 Nov 2024

    Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20755

    Last Modified: 21 Nov 2024

    Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privilege.

    Published: 18 Aug 2021
    4.3
    Medium

    CVE-2021-20754

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.

    Published: 18 Aug 2021
    5.4
    Medium

    CVE-2021-20753

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 18 Aug 2021
    6.1
    Medium

    CVE-2021-39267

    Last Modified: 21 Nov 2024

    Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are not blocked.

    Published: 18 Aug 2021
    6.1
    Medium

    CVE-2021-39268

    Last Modified: 21 Nov 2024

    Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.

    Published: 18 Aug 2021
    0
    Low

    CVE-2021-23161

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 18 Aug 2021
    0
    Low

    CVE-2021-23156

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 18 Aug 2021
    7.8
    High

    CVE-2021-3717

    Last Modified: 21 Nov 2024

    A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2021-37714

    Last Modified: 21 Nov 2024

    jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2021-39293

    Last Modified: 21 Nov 2024

    In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.

    Published: 18 Aug 2021
    8.1
    High

    CVE-2021-29991

    Last Modified: 21 Nov 2024

    Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.

    Published: 18 Aug 2021
    8.8
    High

    CVE-2021-21852

    Last Modified: 21 Nov 2024

    Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

    Published: 18 Aug 2021
    0
    Low

    CVE-2021-3724

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2021-25218

    Last Modified: 21 Nov 2024

    In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the circumstances described above, the named process will terminate due to a failed assertion check. The vulnerability affects only BIND 9 releases 9.16.19, 9.17.16, and release 9.16.19-S1 of the BIND Supported Preview Edition.

    Published: 18 Aug 2021
    7.5
    High

    CVE-2021-0284

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the TCP/IP stack of Juniper Networks Junos OS allows an attacker to send specific sequences of packets to the device thereby causing a Denial of Service (DoS). By repeatedly sending these sequences of packets to the device, an attacker can sustain the Denial of Service (DoS) condition. The device will abnormally shut down as a result of these sent packets. A potential indicator of compromise will be the following message in the log files: "eventd[13955]: SYSTEM_ABNORMAL_SHUTDOWN: System abnormally shut down" This issue is only triggered by traffic destined to the device. Transit traffic will not trigger this issue. This issue affects: Juniper Networks Junos OS 12.3 versions prior to 12.3R12-S19; 15.1 versions prior to 15.1R7-S10; 17.3 versions prior to 17.3R3-S12; 18.4 versions prior to 18.4R2-S9, 18.4R3-S9; 19.1 versions prior to 19.1R3-S7; 19.2 versions prior to 19.2R1-S7, 19.2R3-S3; 19.3 versions prior to 19.3R2-S7, 19.3R3-S3; 19.4 versions prior to 19.4R3-S5; 20.1 versions prior to 20.1R3-S1; 20.2 versions prior to 20.2R3-S2; 20.3 versions prior to 20.3R3-S1; 20.4 versions prior to 20.4R2-S2, 20.4R3; 21.1 versions prior to 21.1R2; 21.2 versions prior to 21.2R1-S1, 21.2R2.

    Published: 17 Aug 2021
    6.1
    Medium

    CVE-2021-39249

    Last Modified: 21 Nov 2024

    Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.

    Published: 17 Aug 2021
    5.4
    Medium

    CVE-2021-39250

    Last Modified: 21 Nov 2024

    Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer header, and the ability of an admin to use the templating engine (e.g., Edit HTML).

    Published: 17 Aug 2021
    8.3
    High

    CVE-2021-28372

    Last Modified: 21 Nov 2024

    ThroughTek's Kalay Platform 2.0 network allows an attacker to impersonate an arbitrary ThroughTek (TUTK) device given a valid 20-byte uniquely assigned identifier (UID). This could result in an attacker hijacking a victim's connection and forcing them into supplying credentials needed to access the victim TUTK device.

    Published: 17 Aug 2021
    6.1
    Medium

    CVE-2020-23341

    Last Modified: 21 Nov 2024

    A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 17 Aug 2021
    7.5
    High

    CVE-2020-23333

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead to a denial of service (DOS).

    Published: 17 Aug 2021
    7.5
    High

    CVE-2020-23334

    Last Modified: 21 Nov 2024

    A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentation fault.

    Published: 17 Aug 2021