CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2021-1496

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges. To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 May 2021
    4.7
    Medium

    CVE-2021-1490

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit this vulnerability by persuading a user to retrieve a crafted file that contains malicious payload and upload it to the affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 6 May 2021
    5.3
    Medium

    CVE-2021-1486

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A successful exploit could allow the attacker to compare the HTTP responses that are returned by the affected system to determine which accounts are valid user accounts.

    Published: 6 May 2021
    5.3
    Medium

    CVE-2021-1478

    Last Modified: 21 Nov 2024

    A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to an unsecured TCP/IP port. An attacker could exploit this vulnerability by accessing the port and restarting the JMX process. A successful exploit could allow the attacker to cause a DoS condition on an affected system.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2021-1468

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 May 2021
    6.7
    Medium

    CVE-2021-1447

    Last Modified: 21 Nov 2024

    A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, local attacker to elevate their privileges to root. This vulnerability is due to a procedural flaw in the password generation algorithm. An attacker could exploit this vulnerability by enabling specific Administrator-only features and connecting to the appliance through the CLI with elevated privileges. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system. To exploit this vulnerability, the attacker must have valid Administrator credentials.

    Published: 6 May 2021
    5.5
    Medium

    CVE-2021-1438

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the CLI. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to read arbitrary files that they originally did not have permissions to access.

    Published: 6 May 2021
    7
    High

    CVE-2021-1429

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges. To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 May 2021
    7
    High

    CVE-2021-1430

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges. To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 May 2021
    7
    High

    CVE-2021-1428

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges. To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 May 2021
    6
    Medium

    CVE-2021-21550

    Last Modified: 21 Nov 2024

    Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability can allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges.

    Published: 6 May 2021
    6
    Medium

    CVE-2021-21527

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE privileges to escalate privileges.

    Published: 6 May 2021
    8
    High

    CVE-2021-21505

    Last Modified: 21 Nov 2024

    Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.

    Published: 6 May 2021
    8.8
    High

    CVE-2021-26543

    Last Modified: 21 Nov 2024

    The "gitDiff" function in Wayfair git-parse <=1.0.4 has a command injection vulnerability. Clients of the git-parse library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. The issue has been resolved in version 1.0.5.

    Published: 6 May 2021
    5.9
    Medium

    CVE-2021-31245

    Last Modified: 21 Nov 2024

    omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing attack.

    Published: 6 May 2021
    8.8
    High

    CVE-2021-31616

    Last Modified: 21 Nov 2024

    Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely over WebUSB.

    Published: 6 May 2021
    6.8
    Medium

    CVE-2021-31532

    Last Modified: 21 Nov 2024

    NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (silicon rev 0A) include an undocumented ROM patch peripheral that allows unsigned, non-persistent modification of the internal ROM.

    Published: 6 May 2021
    6.3
    Medium

    CVE-2021-27216

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2020-28026

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unauthenticated remote attackers to execute arbitrary commands as root.

    Published: 6 May 2021
    7.5
    High

    CVE-2020-28025

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between sig->bodyhash.len and b->bh.len; thus, a crafted DKIM-Signature header might lead to a leak of sensitive information from process memory.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2020-28024

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp_ungetc was only intended to push back characters, but can actually push back non-character error codes such as EOF.

    Published: 6 May 2021
    7.5
    High

    CVE-2020-28023

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to an unauthenticated SMTP client.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2020-28022

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when processing name=value pairs within MAIL FROM and RCPT TO commands.

    Published: 6 May 2021
    8.8
    High

    CVE-2020-28021

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. An authenticated remote SMTP client can insert newline characters into a spool file (which indirectly leads to remote code execution as root) via AUTH= in a MAIL FROM command.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2020-28020

    Last Modified: 21 Nov 2024

    Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging the mishandling of continuation lines during header-length restriction.

    Published: 6 May 2021
    7.5
    High

    CVE-2020-28019

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2020-28018

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2020-28017

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption.

    Published: 6 May 2021
    7.8
    High

    CVE-2020-28016

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase.

    Published: 6 May 2021
    7.8
    High

    CVE-2020-28015

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processes because a recipient address can have a newline character.

    Published: 6 May 2021
    6.1
    Medium

    CVE-2020-28014

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and allows a denial of service because root-owned files can be overwritten.

    Published: 6 May 2021
    7.8
    High

    CVE-2020-28013

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation from any user to root. This occurs because of the interpretation of negative sizes in strncpy.

    Published: 6 May 2021
    7.8
    High

    CVE-2020-28012

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privileged pipe that lacks a close-on-exec flag.

    Published: 6 May 2021
    7.8
    High

    CVE-2020-28011

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause privilege escalation from exim to root.

    Published: 6 May 2021
    7.8
    High

    CVE-2020-28010

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working directory pathname into a buffer that is too small (on some common platforms).

    Published: 6 May 2021
    7.8
    High

    CVE-2020-28009

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are accompanied by unbounded increases in a certain size variable. NOTE: exploitation may be impractical because of the execution time needed to overflow (multiple days).

    Published: 6 May 2021
    7.8
    High

    CVE-2020-28008

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), an attacker can write to a /var/spool/exim4/input spool header file, in which a crafted recipient address can indirectly lead to command execution.

    Published: 6 May 2021
    7.8
    High

    CVE-2020-28007

    Last Modified: 21 Nov 2024

    Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem.

    Published: 6 May 2021
    9.8
    Critical

    CVE-2021-30473

    Last Modified: 21 Nov 2024

    aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.

    Published: 6 May 2021
    6.1
    Medium

    CVE-2021-32052

    Last Modified: 21 Nov 2024

    In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

    Published: 6 May 2021
    3.1
    Low

    CVE-2021-32718

    Last Modified: 21 Nov 2024

    RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially allowing for JavaScript code execution in the context of the page. In order for this to occur, the user must be signed in and have elevated permissions (other user management). The vulnerability is patched in RabbitMQ 3.8.17. As a workaround, disable `rabbitmq_management` plugin and use CLI tools for management operations and Prometheus and Grafana for metrics and monitoring.

    Published: 6 May 2021
    5.3
    Medium

    CVE-2021-21419

    Last Modified: 21 Nov 2024

    Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame. A patch in version 0.31.0 restricts websocket frame to reasonable limits. As a workaround, restricting memory usage via OS limits would help against overall machine exhaustion, but there is no workaround to protect Eventlet process.

    Published: 6 May 2021
    3.1
    Low

    CVE-2021-22211

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2020-19114

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.

    Published: 5 May 2021
    4.9
    Medium

    CVE-2020-23128

    Last Modified: 21 Nov 2024

    Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2020-19113

    Last Modified: 21 Nov 2024

    Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.

    Published: 5 May 2021
    8.8
    High

    CVE-2020-23127

    Last Modified: 21 Nov 2024

    Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2020-19112

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute arbitrary code.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2020-19111

    Last Modified: 21 Nov 2024

    Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication and obtain sensitive information.

    Published: 5 May 2021
    9.8
    Critical

    CVE-2020-19110

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.

    Published: 5 May 2021