CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-0536

    Last Modified: 21 Nov 2024

    In dropFile of WiFiInstaller, there is a way to delete files accessible to CertInstaller due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176756691

    Published: 22 Jun 2021
    6.7
    Medium

    CVE-2021-0535

    Last Modified: 21 Nov 2024

    In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168314741

    Published: 22 Jun 2021
    4.4
    Medium

    CVE-2021-0566

    Last Modified: 21 Nov 2024

    In accessAudioHalPidscpp of TimeCheck.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-175894436

    Published: 22 Jun 2021
    5.5
    Medium

    CVE-2021-0563

    Last Modified: 21 Nov 2024

    In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172908358

    Published: 22 Jun 2021
    5.5
    Medium

    CVE-2021-0562

    Last Modified: 21 Nov 2024

    In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176084648

    Published: 22 Jun 2021
    5.5
    Medium

    CVE-2021-0561

    Last Modified: 21 Nov 2024

    In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683

    Published: 22 Jun 2021
    6.5
    Medium

    CVE-2021-0559

    Last Modified: 21 Nov 2024

    In Lag_max of p_ol_wgh.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172312730

    Published: 22 Jun 2021
    6.5
    Medium

    CVE-2021-0558

    Last Modified: 21 Nov 2024

    In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173473906

    Published: 22 Jun 2021
    5.5
    Medium

    CVE-2021-0556

    Last Modified: 21 Nov 2024

    In getBlockSum of fastcodemb.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172716941

    Published: 22 Jun 2021
    6.4
    Medium

    CVE-2021-0564

    Last Modified: 21 Nov 2024

    In decrypt of CryptoPlugin.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176495665

    Published: 22 Jun 2021
    8.8
    High

    CVE-2021-0557

    Last Modified: 21 Nov 2024

    In setRange of ABuffer.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179046129

    Published: 22 Jun 2021
    7
    High

    CVE-2021-0565

    Last Modified: 21 Nov 2024

    In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174801970

    Published: 22 Jun 2021
    5.5
    Medium

    CVE-2021-0572

    Last Modified: 21 Nov 2024

    In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-177931355

    Published: 22 Jun 2021
    5
    Medium

    CVE-2021-0569

    Last Modified: 21 Nov 2024

    In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174045870

    Published: 22 Jun 2021
    5.5
    Medium

    CVE-2021-0554

    Last Modified: 21 Nov 2024

    In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158482162

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0570

    Last Modified: 21 Nov 2024

    In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-178803845

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0568

    Last Modified: 21 Nov 2024

    In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-170121238

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0567

    Last Modified: 21 Nov 2024

    In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179461812

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0534

    Last Modified: 21 Nov 2024

    In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-170639543

    Published: 22 Jun 2021
    7.8
    High

    CVE-2021-0571

    Last Modified: 21 Nov 2024

    In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possible access to restricted activities due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137395936

    Published: 22 Jun 2021
    7.5
    High

    CVE-2021-0555

    Last Modified: 21 Nov 2024

    In RenderStruct of protostream_objectsource.cc, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179161711

    Published: 22 Jun 2021
    —
    Unknown

    CVE-2010-2485

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jun 2021
    —
    Unknown

    CVE-2010-2486

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jun 2021
    —
    Unknown

    CVE-2010-2475

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-20744

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-20743

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-20742

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-20741

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Hitachi Application Server Help (Hitachi Application Server V10 Manual (Windows) version 10-11-01 and earlier and Hitachi Application Server V10 Manual (UNIX) version 10-11-01 and earlier) allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 22 Jun 2021
    6.5
    Medium

    CVE-2021-20737

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.

    Published: 22 Jun 2021
    9.1
    Critical

    CVE-2021-20736

    Last Modified: 21 Nov 2024

    NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-20735

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earlier, and Delivery slip number mail plugin (3.0 series) 1.0.8 and earlier) allows remote attackers to inject an arbitrary script by executing a specific operation on the management page of EC-CUBE.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-20734

    Last Modified: 20 Feb 2025

    Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 22 Jun 2021
    6.1
    Medium

    CVE-2021-20733

    Last Modified: 21 Nov 2024

    Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

    Published: 22 Jun 2021
    4.4
    Medium

    CVE-2021-0605

    Last Modified: 21 Nov 2024

    In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-110373476

    Published: 22 Jun 2021
    6.7
    Medium

    CVE-2021-0606

    Last Modified: 21 Nov 2024

    In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168034487

    Published: 22 Jun 2021
    2.9
    Low

    CVE-2021-34428

    Last Modified: 21 Nov 2024

    For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

    Published: 22 Jun 2021
    7.5
    High

    CVE-2021-35197

    Last Modified: 21 Nov 2024

    In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).

    Published: 22 Jun 2021
    6.5
    Medium

    CVE-2021-36976

    Last Modified: 3 Nov 2025

    libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

    Published: 22 Jun 2021
    9.8
    Critical

    CVE-2010-1435

    Last Modified: 21 Nov 2024

    Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently retrieve password reset tokens from the database through an already existing SQL injection vector. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.

    Published: 21 Jun 2021
    7.5
    High

    CVE-2010-1434

    Last Modified: 21 Nov 2024

    Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.

    Published: 21 Jun 2021
    7.8
    High

    CVE-2021-35196

    Last Modified: 21 Nov 2024

    Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is insecure deserialization via the pickle.load() function in settings.py. NOTE: the vendor's position is that the product is not intended for opening an untrusted project file

    Published: 21 Jun 2021
    9.8
    Critical

    CVE-2010-1433

    Last Modified: 21 Nov 2024

    Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.

    Published: 21 Jun 2021
    7.5
    High

    CVE-2010-1432

    Last Modified: 21 Nov 2024

    Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.

    Published: 21 Jun 2021
    —
    Unknown

    CVE-2010-0413

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Jun 2021
    5
    Medium

    CVE-2021-34389

    Last Modified: 21 Nov 2024

    Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check can allow a local user through a malicious client to access memory from the heap in the TrustZone, which may lead to information disclosure.

    Published: 21 Jun 2021
    6.3
    Medium

    CVE-2021-34388

    Last Modified: 21 Nov 2024

    Bootloader contains a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.

    Published: 21 Jun 2021
    6.3
    Medium

    CVE-2021-34387

    Last Modified: 21 Nov 2024

    The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.

    Published: 21 Jun 2021
    6.3
    Medium

    CVE-2021-34386

    Last Modified: 21 Nov 2024

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calloc size calculation can cause the multiplication of count and size can overflow, which might lead to heap overflows.

    Published: 21 Jun 2021
    6.8
    Medium

    CVE-2021-32698

    Last Modified: 21 Nov 2024

    eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on behalf of the server. It is "blind" because the attacker cannot see the result of the request. Issue has been patched in eLabFTW 4.0.0.

    Published: 21 Jun 2021
    7.5
    High

    CVE-2021-29061

    Last Modified: 21 Nov 2024

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs.

    Published: 21 Jun 2021