Latest CVE Feed
-
5.5
MEDIUMCVE-2021-42265
Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR... Read more
- Published: Sep. 07, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUM- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-42264
Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context... Read more
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-42196
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function traits_parse() located in abc.c. It allows an attacker to cause Denial of Service.... Read more
Affected Products : swftools- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-42111
An issue was discovered in the RCDevs OpenOTP app 1.4.13 and 1.4.14 for iOS. If it is installed on a jailbroken device, it is possible to retrieve the PIN code used to access the application. The IOS app version 1.4.1631262629 resolves this issue by stori... Read more
Affected Products : openotp_token- Published: Nov. 10, 2021
- Modified: May. 30, 2025
-
5.5
MEDIUMCVE-2021-42015
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications using Mendix 8 (All versions < V8.18.12), Mendix Applications using Mendix 9 (All versions < V9.6.1). Applications built with affected... Read more
Affected Products : mendix- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-42263
Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context... Read more
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41802
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault ... Read more
Affected Products : vault- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-54096
Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy.... Read more
- Published: Dec. 12, 2024
- Modified: Jan. 10, 2025
-
5.5
MEDIUMCVE-2021-41849
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipmen... Read more
Affected Products : g90_firmware g9_firmware tommy_3_firmware tommy_3_plus_firmware simo_firmware g90 g9 tommy_3 tommy_3_plus simo- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41496
Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative values. NOTE: The vendor does not agree this is a vulnerabi... Read more
Affected Products : numpy- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41458
In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.... Read more
Affected Products : mp4box- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUM- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41343
Windows Fast FAT File System Driver Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +12 more products- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41199
TensorFlow is an open source platform for machine learning. In affected versions if `tf.image.resize` is called with a large input argument then the TensorFlow process will crash due to a `CHECK`-failure caused by an overflow. The number of elements in th... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41197
TensorFlow is an open source platform for machine learning. In affected versions TensorFlow allows tensor to have a large number of dimensions and each dimension can be as large as desired. However, the total number of elements in a tensor must fit within... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41222
TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trigger a segfault is an attacker supplies negative arguments. This occurs whenever `size_splits` contains more than one value and at least... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41200
TensorFlow is an open source platform for machine learning. In affected versions if `tf.summary.create_file_writer` is called with non-scalar arguments code crashes due to a `CHECK`-fail. The fix will be included in TensorFlow 2.7.0. We will also cherrypi... Read more
Affected Products : tensorflow- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41061
In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots.... Read more
Affected Products : riot- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41043
Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.... Read more
Affected Products : tcpslice- Published: Jan. 05, 2022
- Modified: Nov. 21, 2024