Latest CVE Feed
-
6.5
MEDIUMCVE-2021-3912
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).... Read more
- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3911
If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.... Read more
- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3910
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).... Read more
- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3909
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a res... Read more
- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3908
OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.... Read more
- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3907
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow fo... Read more
- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3906
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type... Read more
Affected Products : bookstack- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-3905
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.... Read more
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-3904
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : grav- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGH- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-3901
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : firefly_iii- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-3900
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : firefly_iii- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-3898
Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker.... Read more
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3897
An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SM... Read more
Affected Products : nextscale_n1200_enclosure_firmware thinkagile_hx_enclosure_certified_node_firmware thinkagile_vx_enclosure_firmware thinksystem_d2_enclosure_firmware nextscale_fan_power_controller_firmware nextscale_n1200_enclosure thinkagile_hx_enclosure_certified_node thinkagile_vx_enclosure thinksystem_d2_enclosure nextscale_fan_power_controller- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-3889
libmobi is vulnerable to Use of Out-of-range Pointer Offset... Read more
Affected Products : libmobi- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-3888
libmobi is vulnerable to Use of Out-of-range Pointer Offset... Read more
Affected Products : libmobi- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-3882
LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain ... Read more
Affected Products : ledgersmb- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-3879
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : snipe-it- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-3875
vim is vulnerable to Heap-based Buffer Overflow... Read more
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024