CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2021-33182

    Last Modified: 14 Jan 2025

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to read limited files via unspecified vectors.

    Published: 1 Jun 2021
    7.7
    High

    CVE-2021-33184

    Last Modified: 21 Nov 2024

    Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 1 Jun 2021
    7.9
    High

    CVE-2021-33183

    Last Modified: 21 Nov 2024

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker before 18.09.0-0515 allows local users to read or write arbitrary files via unspecified vectors.

    Published: 1 Jun 2021
    7.8
    High

    CVE-2021-29088

    Last Modified: 14 Jan 2025

    Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors.

    Published: 1 Jun 2021
    8.8
    High

    CVE-2021-29092

    Last Modified: 21 Nov 2024

    Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 1 Jun 2021
    7.3
    High

    CVE-2021-33180

    Last Modified: 21 Nov 2024

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Jun 2021
    0
    Low

    CVE-2021-34183

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 1 Jun 2021
    0
    Low

    CVE-2021-3587

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-38208. Reason: This candidate is a reservation duplicate of CVE-2021-38208. Notes: All CVE users should reference CVE-2021-38208 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 1 Jun 2021
    7.5
    High

    CVE-2021-31684

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.

    Published: 1 Jun 2021
    8.8
    High

    CVE-2020-17541

    Last Modified: 21 Nov 2024

    Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

    Published: 1 Jun 2021
    7.5
    High

    CVE-2021-32625

    Last Modified: 21 Nov 2024

    Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer, could be exploited using the STRALGO LCS command to corrupt the heap and potentially result with remote code execution. This is a result of an incomplete fix by CVE-2021-29477. The problem is fixed in version 6.2.4 and 6.0.14. An additional workaround to mitigate the problem without patching the redis-server executable is to use ACL configuration to prevent clients from using the STRALGO LCS command. On 64 bit systems which have the fixes of CVE-2021-29477 (6.2.3 or 6.0.13), it is sufficient to make sure that the proto-max-bulk-len config parameter is smaller than 2GB (default is 512MB).

    Published: 1 Jun 2021
    7.5
    High

    CVE-2021-33503

    Last Modified: 21 Nov 2024

    An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

    Published: 1 Jun 2021
    7.1
    High

    CVE-2021-29964

    Last Modified: 21 Nov 2024

    A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.

    Published: 1 Jun 2021
    8.8
    High

    CVE-2021-29967

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.

    Published: 1 Jun 2021
    10
    Critical

    CVE-2020-4561

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903.

    Published: 31 May 2021
    8.8
    High

    CVE-2020-4520

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.

    Published: 31 May 2021
    5.4
    Medium

    CVE-2020-4354

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178506.

    Published: 31 May 2021
    8.2
    High

    CVE-2020-4300

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 176607.

    Published: 31 May 2021
    7.1
    High

    CVE-2019-4730

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172533.

    Published: 31 May 2021
    7.5
    High

    CVE-2019-4724

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130.

    Published: 31 May 2021
    7.5
    High

    CVE-2019-4723

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129.

    Published: 31 May 2021
    4.3
    Medium

    CVE-2019-4722

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due to mishandling of certain error conditions. IBM X-Force ID: 172128.

    Published: 31 May 2021
    5.4
    Medium

    CVE-2019-4653

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170964.

    Published: 31 May 2021
    6.5
    Medium

    CVE-2019-4471

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 163780.

    Published: 31 May 2021
    7.8
    High

    CVE-2021-29665

    Last Modified: 21 Nov 2024

    IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.

    Published: 31 May 2021
    5.3
    Medium

    CVE-2021-20585

    Last Modified: 21 Nov 2024

    IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system. IBM X-Force ID: 199398.

    Published: 31 May 2021
    7.5
    High

    CVE-2021-20576

    Last Modified: 21 Nov 2024

    IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.

    Published: 31 May 2021
    3.3
    Low

    CVE-2021-20575

    Last Modified: 21 Nov 2024

    IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.

    Published: 31 May 2021
    5.3
    Medium

    CVE-2021-23388

    Last Modified: 21 Nov 2024

    The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via email validation.

    Published: 31 May 2021
    9.8
    Critical

    CVE-2020-10666

    Last Modified: 21 Nov 2024

    The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL variable to an AMI command.

    Published: 31 May 2021
    9.8
    Critical

    CVE-2021-30180

    Last Modified: 21 Nov 2024

    Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.

    Published: 31 May 2021
    9.8
    Critical

    CVE-2021-30179

    Last Modified: 21 Nov 2024

    Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are handled by the GenericFilter which will find the service and method specified in the first arguments of the invocation and use the Java Reflection API to make the final call. The signature for the $invoke or $invokeAsync methods is Ljava/lang/String;[Ljava/lang/String;[Ljava/lang/Object; where the first argument is the name of the method to invoke, the second one is an array with the parameter types for the method being invoked and the third one is an array with the actual call arguments. In addition, the caller also needs to set an RPC attachment specifying that the call is a generic call and how to decode the arguments. The possible values are: - true - raw.return - nativejava - bean - protobuf-json An attacker can control this RPC attachment and set it to nativejava to force the java deserialization of the byte array located in the third argument.

    Published: 31 May 2021
    6.1
    Medium

    CVE-2021-25640

    Last Modified: 21 Nov 2024

    In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.

    Published: 31 May 2021
    9.8
    Critical

    CVE-2021-33790

    Last Modified: 21 Nov 2024

    The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.ExtendedPacketBuffer. An attacker can instantiate any class on the classpath with any data. A class usable for exploitation might or might not be present, depending on what Minecraft modifications are installed.

    Published: 31 May 2021
    7.5
    High

    CVE-2019-14839

    Last Modified: 21 Nov 2024

    It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.

    Published: 31 May 2021
    7.8
    High

    CVE-2021-3624

    Last Modified: 21 Nov 2024

    There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system.

    Published: 31 May 2021
    5.5
    Medium

    CVE-2021-38206

    Last Modified: 21 Nov 2024

    The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers to cause a denial of service (NULL pointer dereference in the radiotap parser) by injecting a frame with 802.11a rates.

    Published: 31 May 2021
    5.5
    Medium

    CVE-2021-38208

    Last Modified: 21 Nov 2024

    net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NULL pointer dereference and BUG) by making a getsockname call after a certain type of failure of a bind call.

    Published: 31 May 2021
    7.5
    High

    CVE-2021-45485

    Last Modified: 21 Nov 2024

    In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.

    Published: 31 May 2021
    9.8
    Critical

    CVE-2021-33564

    Last Modified: 21 Nov 2024

    An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

    Published: 29 May 2021
    9.8
    Critical

    CVE-2021-31703

    Last Modified: 21 Nov 2024

    Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user.

    Published: 29 May 2021
    7.5
    High

    CVE-2021-31702

    Last Modified: 21 Nov 2024

    Frontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated by submitting 127.0.0.1 multiple times for DoS.

    Published: 29 May 2021
    9.8
    Critical

    CVE-2021-30461

    Last Modified: 21 Nov 2024

    A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.

    Published: 29 May 2021
    9.8
    Critical

    CVE-2021-25641

    Last Modified: 21 Nov 2024

    Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by tampering with the byte preamble flags, aka, not following the server's instruction. This means that if a weak deserializer such as the Kryo and FST are somehow in code scope (e.g. if Kryo is somehow a part of a dependency), a remote unauthenticated attacker can tell the Provider to use the weak deserializer, and then proceed to exploit it.

    Published: 29 May 2021
    9.8
    Critical

    CVE-2021-30181

    Last Modified: 21 Nov 2024

    Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code.

    Published: 29 May 2021
    8
    High

    CVE-2021-32647

    Last Modified: 21 Nov 2024

    Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication Remote Code Execution (RCE). The [`CreatePlace`](https://github.com/NationalSecurityAgency/emissary/blob/30c54ef16c6eb6ed09604a929939fb9f66868382/src/main/java/emissary/server/mvc/internal/CreatePlaceAction.java#L36) REST endpoint accepts an `sppClassName` parameter which is used to load an arbitrary class. This class is later instantiated using a constructor with the following signature: `<constructor>(String, String, String)`. An attacker may find a gadget (class) in the application classpath that could be used to achieve Remote Code Execution (RCE) or disrupt the application. Even though the chances to find a gadget (class) that allow arbitrary code execution are low, an attacker can still find gadgets that could potentially crash the application or leak sensitive data. As a work around disable network access to Emissary from untrusted sources.

    Published: 28 May 2021
    8.8
    High

    CVE-2021-32620

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 12.10.2, a user disabled on a wiki using email verification for registration canouldre-activate themself by using the activation link provided for his registration. The problem has been patched in the following versions of XWiki: 11.10.13, 12.6.7, 12.10.2, 13.0. It is possible to workaround the issue by resetting the `validkey` property of the disabled XWiki users. This can be done by editing the user profile with object editor.

    Published: 28 May 2021
    8.8
    High

    CVE-2021-32621

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 12.6.7 and 12.10.3, a user without Script or Programming right is able to execute script requiring privileges by editing gadget titles in the dashboard. The issue has been patched in XWiki 12.6.7, 12.10.3 and 13.0RC1.

    Published: 28 May 2021
    5.7
    Medium

    CVE-2021-29507

    Last Modified: 21 Nov 2024

    GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vulnerable component to crash. All the applications which are using the configuration file could fail to generate their dlt logs in system. As of time of publication, no patch exists. As a workaround, one may check the integrity of information in configuration file manually.

    Published: 28 May 2021
    9.8
    Critical

    CVE-2021-32619

    Last Modified: 21 Nov 2024

    Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through `import()` or `new Worker` might have been able to bypass network and file system permission checks when statically importing other modules. The vulnerability has been patched in Deno release 1.10.2.

    Published: 28 May 2021