βΌ CVE-2021-44044 βΌ
π Read
via "National Vulnerability Database".
An out-of-bounds write vulnerability exists when reading a JPG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists with parsing JPG files. Crafted data in a JPG (4 extraneous bytes before the marker 0xca) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.π Read
via "National Vulnerability Database".
βΌ CVE-2021-37253 βΌ
π Read
via "National Vulnerability Database".
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers).π Read
via "National Vulnerability Database".
βΌ CVE-2021-44048 βΌ
π Read
via "National Vulnerability Database".
An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer before 2022.11. The specific issue exists after loading TIF files. Crafted data in a TIF file can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44046 βΌ
π Read
via "National Vulnerability Database".
An out-of-bounds write vulnerability exists when reading U3D files in Open Design Alliance PRC SDK before 2022.11. An unchecked return value of a function (verifying input data from a U3D file) leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44047 βΌ
π Read
via "National Vulnerability Database".
A use-after-free vulnerability exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists with parsing DWF/DWFX files. Crafted data in a DWF/DWFX file and lack of proper validation of input data can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.π Read
via "National Vulnerability Database".
βΌ CVE-2021-44045 βΌ
π Read
via "National Vulnerability Database".
An out-of-bounds write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DGN files. Crafted data in a DGN file and lack of proper validation for the XFAT sectors count can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43035 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote code execution was possible, leading to full access to the postgres user account.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43041 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43036 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43043 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43033 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server) being passed to system calls.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43040 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43044 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43034 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43038 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43039 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43037 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.π Read
via "National Vulnerability Database".
βΌ CVE-2021-43042 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated attacker.π Read
via "National Vulnerability Database".
ποΈ Crypto-exchange BitMart reports $150 million theft following hack ποΈ
π Read
via "The Daily Swig".
Security firm said attackers executed a βtransfer-out, swap, and washβπ Read
via "The Daily Swig".
The Daily Swig | Cybersecurity news and views
Crypto-exchange BitMart reports $150 million theft following hack
Security firm said attackers executed a βtransfer-out, swap, and washβ
βΌ CVE-2021-4069 βΌ
π Read
via "National Vulnerability Database".
vim is vulnerable to Use After Freeπ Read
via "National Vulnerability Database".
βΌ CVE-2021-43469 βΌ
π Read
via "National Vulnerability Database".
VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.π Read
via "National Vulnerability Database".