Latest CVE Feed
-
8.8
HIGHCVE-2021-39527
An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow.... Read more
Affected Products : libredwg- EPSS Score: %0.35
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39525
An issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-based buffer overflow.... Read more
Affected Products : libredwg- EPSS Score: %0.35
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39523
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service.... Read more
Affected Products : libredwg- EPSS Score: %0.24
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39522
An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow.... Read more
Affected Products : libredwg- EPSS Score: %0.38
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39521
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.... Read more
Affected Products : libredwg- EPSS Score: %0.24
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39520
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PushReconstructedData() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.... Read more
Affected Products : libjpeg- EPSS Score: %0.24
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39519
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData() located in blockbitmaprequester.cpp It allows an attacker to cause Denial of Service.... Read more
Affected Products : libjpeg- EPSS Score: %0.24
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39518
An issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow.... Read more
Affected Products : libjpeg- EPSS Score: %0.27
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39517
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::ReconstructUnsampled() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.... Read more
Affected Products : libjpeg- EPSS Score: %0.26
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39516
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function HuffmanDecoder::Get() located in huffmandecoder.hpp. It allows an attacker to cause Denial of Service.... Read more
Affected Products : libjpeg- EPSS Score: %0.26
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39515
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function SampleInterleavedLSScan::ParseMCU() located in sampleinterleavedlsscan.cpp. It allows an attacker to cause Denial of Service.... Read more
Affected Products : libjpeg- EPSS Score: %0.26
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39514
An issue was discovered in libjpeg through 2020021. An uncaught floating point exception in the function ACLosslessScan::ParseMCU() located in aclosslessscan.cpp. It allows an attacker to cause Denial of Service.... Read more
Affected Products : libjpeg- EPSS Score: %0.26
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39510
An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This ca... Read more
- EPSS Score: %8.84
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39509
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can l... Read more
- EPSS Score: %21.23
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-39503
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.... Read more
Affected Products : phpmywind- EPSS Score: %3.28
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39501
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.... Read more
Affected Products : eyoucms- EPSS Score: %38.84
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39500
Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.... Read more
Affected Products : eyoucms- EPSS Score: %1.11
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39499
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.... Read more
Affected Products : eyoucms- EPSS Score: %0.40
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39497
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.... Read more
Affected Products : eyoucms- EPSS Score: %1.21
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39496
Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.... Read more
Affected Products : eyoucms- EPSS Score: %0.21
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024