Latest CVE Feed
-
7.5
HIGHCVE-2021-45487
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.... Read more
Affected Products : netbsd- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-45486
In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small.... Read more
- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45485
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IP... Read more
- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45484
In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.... Read more
Affected Products : netbsd- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45483
In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-30889.... Read more
Affected Products : webkitgtk- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45482
In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability than CVE-2021-30889.... Read more
Affected Products : webkitgtk- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45481
In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create, leading to a segmentation violation and application crash, a different vulnerability than CVE-2021-30889.... Read more
Affected Products : webkitgtk- Published: Dec. 25, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45480
An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances.... Read more
- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45479
Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS.This issue affects Library Automation System: before 19.2. ... Read more
Affected Products : library_automation_system- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45478
Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users.This issue affects Library Automation System: before 19.2. ... Read more
Affected Products : library_automation_system- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-45477
Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users.This issue affects Library Automation System: before 19.2. ... Read more
Affected Products : library_automation_system- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45476
Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnerability.... Read more
Affected Products : library_automation_system- Published: Oct. 27, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45475
Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosure vulnerability.... Read more
Affected Products : library_automation_system- Published: Oct. 27, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45474
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.... Read more
- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45473
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).... Read more
- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-45472
In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.... Read more
- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-45471
In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.... Read more
- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-45470
lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.... Read more
Affected Products : cve-search- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-45469
In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.... Read more
Affected Products : linux_kernel fedora debian_linux h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s +9 more products- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45468
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to web servers behind the WAF.... Read more
Affected Products : web_application_firewall- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024