Latest CVE Feed
-
10.0
CRITICALCVE-2021-40419
A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequence of requests to trigger this vulne... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40418
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUID that was parsed from a frame within the video container. Upon destruction ... Read more
Affected Products : davinci_resolve- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40417
When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate th... Read more
Affected Products : davinci_resolve- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40416
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any logged-in users. A... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-40415
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In cgi_check_ability the Format API does not have a specific case, the user permission will default to 7. Th... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-40414
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The SetMdAlarm API sets the movement detection parameters, giving the ability to set the sensitivity of the ... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-40413
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W fi... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-40412
An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname variable, that has the value of the name parameter provided through the SetDevName API, is not validated p... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-40411
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6] the dns_data->dns2 variable, that has the value of the dns2 parameter provided through the SetLocalLink API, is not v... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-40410
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4] the dns_data->dns1 variable, that has the value of the dns1 parameter provided through the SetLocal API, is not valid... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40409
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->password variable, that has the value of the password parameter provided throug... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40408
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->username variable, that has the value of the userName parameter provided throug... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40406
A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigg... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-40405
A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.... Read more
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-40404
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulner... Read more
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-40403
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a struc... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2021-40402
An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 and 2.8.0. A specially-crafted Gerber file can lead to information disclosu... Read more
Affected Products : gerbv- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-40401
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a mali... Read more
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2021-40400
An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information di... Read more
Affected Products : gerbv- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40399
An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide ... Read more
- Published: May. 12, 2022
- Modified: Nov. 21, 2024