CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-28131

    Last Modified: 21 Nov 2024

    Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with specially constructed requests. This means the attacker is able to execute statements for which they don't have the necessary privileges otherwise. Impala deployments with Apache Sentry or Apache Ranger authorization enabled may be vulnerable to privilege escalation if an authenticated attacker is able to hijack a session or query from another authenticated user with privileges not assigned to the attacker. Impala deployments with audit logging enabled may be vulnerable to incorrect audit logging as a user could undertake actions that were logged under the name of a different authenticated user. Constructing an attack requires a high degree of technical sophistication and access to the Impala system as an authenticated user. Mitigation: If an Impala deployment uses Apache Sentry, Apache Ranger or audit logging, then users should upgrade to a version of Impala with the fix for IMPALA-10600. The Impala 4.0 release includes this fix. This hides session secrets from the logs to eliminate the risk of any attack using this mechanism. In lieu of an upgrade, restricting access to logs that expose secrets will reduce the risk of an attack. Restricting access to the Impala deployment to trusted users will also reduce the risk of an attack. Log redaction techniques can be used to redact secrets from the logs.

    Published: 22 Jul 2021
    7.8
    High

    CVE-2021-36934

    Last Modified: 10 Aug 2026

    An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have the ability to execute code on a victim system to exploit this vulnerability. After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies.

    Published: 22 Jul 2021
    5.5
    Medium

    CVE-2021-1096

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where dereferencing a NULL pointer may lead to a system crash.

    Published: 22 Jul 2021
    7.1
    High

    CVE-2021-1092

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in potential denial of service or data loss.

    Published: 22 Jul 2021
    7.1
    High

    CVE-2021-1091

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or denial of service.

    Published: 22 Jul 2021
    7.8
    High

    CVE-2021-1089

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in nvidia-smi where an uncontrolled DLL loading path may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

    Published: 22 Jul 2021
    6.1
    Medium

    CVE-2021-1094

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.

    Published: 22 Jul 2021
    7.5
    High

    CVE-2020-22283

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the icmp6_send_response_with_addrs_and_netif() function of Free Software Foundation lwIP version git head allows attackers to access sensitive information via a crafted ICMPv6 packet.

    Published: 22 Jul 2021
    5.5
    Medium

    CVE-2021-1095

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.

    Published: 22 Jul 2021
    5.3
    Medium

    CVE-2021-32785

    Last Modified: 21 Nov 2024

    mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured to use an unencrypted Redis cache (`OIDCCacheEncrypt off`, `OIDCSessionType server-cache`, `OIDCCacheType redis`), `mod_auth_openidc` wrongly performed argument interpolation before passing Redis requests to `hiredis`, which would perform it again and lead to an uncontrolled format string bug. Initial assessment shows that this bug does not appear to allow gaining arbitrary code execution, but can reliably provoke a denial of service by repeatedly crashing the Apache workers. This bug has been corrected in version 2.4.9 by performing argument interpolation only once, using the `hiredis` API. As a workaround, this vulnerability can be mitigated by setting `OIDCCacheEncrypt` to `on`, as cache keys are cryptographically hashed before use when this option is enabled.

    Published: 22 Jul 2021
    4.7
    Medium

    CVE-2021-32786

    Last Modified: 21 Nov 2024

    mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs the same way as most browsers do. As a result, this function can be bypassed and leads to an Open Redirect vulnerability in the logout functionality. This bug has been fixed in version 2.4.9 by replacing any backslash of the URL to redirect with slashes to address a particular breaking change between the different specifications (RFC2396 / RFC3986 and WHATWG). As a workaround, this vulnerability can be mitigated by configuring `mod_auth_openidc` to only allow redirection whose destination matches a given regular expression.

    Published: 22 Jul 2021
    5.3
    Medium

    CVE-2021-36157

    Last Modified: 21 Nov 2024

    An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.)

    Published: 22 Jul 2021
    7.1
    High

    CVE-2021-1090

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.

    Published: 22 Jul 2021
    6.2
    Medium

    CVE-2021-1093

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may lead to denial of service or system crash.

    Published: 22 Jul 2021
    5.5
    Medium

    CVE-2021-37220

    Last Modified: 21 Nov 2024

    MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

    Published: 21 Jul 2021
    6.8
    Medium

    CVE-2021-32776

    Last Modified: 21 Nov 2024

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.

    Published: 21 Jul 2021
    7.7
    High

    CVE-2021-32775

    Last Modified: 21 Nov 2024

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.

    Published: 21 Jul 2021
    8.8
    High

    CVE-2021-32756

    Last Modified: 21 Nov 2024

    ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module of ManageIQ where a low privilege user could enter a crafted Ruby string which would be evaluated. Successful exploitation will allow an attacker to execute arbitrary code with root privileges on the host system. There are patches for this issue in releases named jansa-4, kasparov-2, and lasker-1. If possible, restrict users, via RBAC, to only the part of the application that they need access to. While MiqExpression is widely used throughout the product, restricting users can limit the surface of the attack.

    Published: 21 Jul 2021
    7.2
    High

    CVE-2021-34816

    Last Modified: 21 Nov 2024

    An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.

    Published: 21 Jul 2021
    7.3
    High

    CVE-2021-32745

    Last Modified: 21 Nov 2024

    Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online prior to version 6.4.9-5. An attacker could inject unescaped HTML into a variable as they created the Collabora Online iframe, and execute scripts inside the context of the Collabora Online iframe. This would give access to a small set of user settings stored in the browser, as well as the session's authentication token which was also passed in at iframe creation time. The issue is patched in Collabora Online 6.4.9-5. Collabora Online 4.2 is not affected.

    Published: 21 Jul 2021
    7.8
    High

    CVE-2021-35482

    Last Modified: 21 Nov 2024

    An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70. An attacker in the local network is able to achieve Remote Code Execution (with user privileges of the local user) on any device that tries to connect to a WePresent presentation system.

    Published: 21 Jul 2021
    8.8
    High

    CVE-2020-19499

    Last Modified: 21 Nov 2024

    An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.

    Published: 21 Jul 2021
    8.8
    High

    CVE-2020-19498

    Last Modified: 21 Nov 2024

    Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.

    Published: 21 Jul 2021
    8.8
    High

    CVE-2020-19497

    Last Modified: 21 Nov 2024

    Integer overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows attackers to cause a Denial of Service or possibly other unspecified impacts.

    Published: 21 Jul 2021
    7.8
    High

    CVE-2020-19492

    Last Modified: 21 Nov 2024

    There is a floating point exception in ReadImage that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

    Published: 21 Jul 2021
    7.8
    High

    CVE-2020-19491

    Last Modified: 21 Nov 2024

    There is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19490

    Last Modified: 21 Nov 2024

    tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19488

    Last Modified: 21 Nov 2024

    An issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due to an invalid read on function ilst_item_Read.

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19481

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid memory read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file.

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19475

    Last Modified: 21 Nov 2024

    An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 2 .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19474

    Last Modified: 21 Nov 2024

    An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After Free .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19473

    Last Modified: 21 Nov 2024

    An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncaught floating point exception.

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19472

    Last Modified: 21 Nov 2024

    An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 2 .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19471

    Last Modified: 21 Nov 2024

    An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19470

    Last Modified: 21 Nov 2024

    An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL pointer dereference (invalid read of size 1) .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19469

    Last Modified: 21 Nov 2024

    An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 8 .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19468

    Last Modified: 21 Nov 2024

    An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null pointer derefenrece (invalid read of size 8) .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19467

    Last Modified: 21 Nov 2024

    An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Illegal Use After Free .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19466

    Last Modified: 21 Nov 2024

    An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 1 .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19465

    Last Modified: 21 Nov 2024

    An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19464

    Last Modified: 21 Nov 2024

    An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow .

    Published: 21 Jul 2021
    5.5
    Medium

    CVE-2020-19463

    Last Modified: 21 Nov 2024

    An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.

    Published: 21 Jul 2021
    —
    Unknown

    CVE-2021-23410

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Jul 2021
    6.1
    Medium

    CVE-2020-22150

    Last Modified: 21 Nov 2024

    A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.

    Published: 21 Jul 2021
    6.1
    Medium

    CVE-2020-22148

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.

    Published: 21 Jul 2021
    9.8
    Critical

    CVE-2021-32744

    Last Modified: 21 Nov 2024

    Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gain access to files which are currently opened by other users in the Collabora Online editor. For successful exploitation the attacker is required to guess the file identifier - the predictability of this file identifier is dependent on external file-storage implementations (this is a potential "IDOR" - Insecure Direct Object Reference - vulnerability). Versions 4.2.17-1 and 6.4.9-5 contain patches for this issue. There is no known workaround except updating the Collabora Online application to one of the patched releases.

    Published: 21 Jul 2021
    5.4
    Medium

    CVE-2021-23408

    Last Modified: 21 Nov 2024

    This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __proto__ payload.

    Published: 21 Jul 2021
    8
    High

    CVE-2021-21407

    Last Modified: 21 Nov 2024

    Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0.

    Published: 21 Jul 2021
    5.8
    Medium

    CVE-2021-21406

    Last Modified: 21 Nov 2024

    Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.

    Published: 21 Jul 2021
    5.4
    Medium

    CVE-2021-23411

    Last Modified: 21 Nov 2024

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction.

    Published: 21 Jul 2021