โผ CVE-2021-45773 โผ
๐ Read
via "National Vulnerability Database".
A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-39681 โผ
๐ Read
via "National Vulnerability Database".
In delete_protocol of main.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-200251074References: N/A๐ Read
via "National Vulnerability Database".
โผ CVE-2021-23138 โผ
๐ Read
via "National Vulnerability Database".
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-39626 โผ
๐ Read
via "National Vulnerability Database".
In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-194695497๐ Read
via "National Vulnerability Database".
โผ CVE-2021-0959 โผ
๐ Read
via "National Vulnerability Database".
In jit_memory_region.cc, there is a possible bypass of memory restrictions due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-200284993๐ Read
via "National Vulnerability Database".
โผ CVE-2022-21137 โผ
๐ Read
via "National Vulnerability Database".
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-45775 โผ
๐ Read
via "National Vulnerability Database".
GNU Inetutils 2.2.16-cf091 was discovered to contain an infinite loop in domacro at domacro.c.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-45769 โผ
๐ Read
via "National Vulnerability Database".
A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-45779 โผ
๐ Read
via "National Vulnerability Database".
A NULL pointer dereference in unsetcmd() at inetutils/telnet/commands.c of GNU Inetutils v2.2.16-cf091 can lead to a segmentation fault or application crash.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-23157 โผ
๐ Read
via "National Vulnerability Database".
WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-39621 โผ
๐ Read
via "National Vulnerability Database".
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-185126319๐ Read
via "National Vulnerability Database".
โผ CVE-2021-45068 โผ
๐ Read
via "National Vulnerability Database".
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-45763 โผ
๐ Read
via "National Vulnerability Database".
GPAC v1.1.0 was discovered to contain an invalid call in the function gf_node_changed(). This vulnerability can lead to a Denial of Service (DoS).๐ Read
via "National Vulnerability Database".
โผ CVE-2021-44743 โผ
๐ Read
via "National Vulnerability Database".
Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-1035 โผ
๐ Read
via "National Vulnerability Database".
In setLaunchIntent of BluetoothDevicePickerPreferenceController.java, there is a possible way to invoke an arbitrary broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-12Android ID: A-195668284๐ Read
via "National Vulnerability Database".
โผ CVE-2022-22290 โผ
๐ Read
via "National Vulnerability Database".
Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-28506 โผ
๐ Read
via "National Vulnerability Database".
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-28500 โผ
๐ Read
via "National Vulnerability Database".
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA APIรขโฌโขs by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-39627 โผ
๐ Read
via "National Vulnerability Database".
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-185126549๐ Read
via "National Vulnerability Database".
โผ CVE-2021-42067 โผ
๐ Read
via "National Vulnerability Database".
In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial of service is possible.๐ Read
via "National Vulnerability Database".
โผ CVE-2021-46195 โผ
๐ Read
via "National Vulnerability Database".
GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.๐ Read
via "National Vulnerability Database".