Latest CVE Feed
-
7.5
HIGHCVE-2021-38387
In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and waiting forever, which may cause excessive CPU consumption.... Read more
- EPSS Score: %0.33
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38386
In Contiki 3.0, a buffer overflow in the Telnet service allows remote attackers to cause a denial of service because the ls command is mishandled when a directory has many files with long names.... Read more
- EPSS Score: %0.60
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38385
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.... Read more
Affected Products : tor- EPSS Score: %0.63
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38384
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status co... Read more
Affected Products : serverless_offline- EPSS Score: %0.33
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38383
OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c.... Read more
Affected Products : owntone- EPSS Score: %0.42
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-38382
Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.... Read more
- EPSS Score: %0.22
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-38381
Live555 through 1.08 does not handle MPEG-1 or 2 files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.... Read more
- EPSS Score: %0.22
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38380
Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An attacker can leverage this to launch a DoS attack.... Read more
- EPSS Score: %0.28
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38379
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.... Read more
Affected Products : cfengine- EPSS Score: %0.03
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38378
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.... Read more
- EPSS Score: %0.25
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38377
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.... Read more
- EPSS Score: %0.30
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-38376
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.... Read more
- EPSS Score: %0.27
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38375
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.... Read more
- EPSS Score: %0.34
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38374
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.... Read more
- EPSS Score: %0.38
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-38373
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.... Read more
Affected Products : kmail- EPSS Score: %0.16
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38372
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.... Read more
- EPSS Score: %0.31
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38371
The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.... Read more
Affected Products : exim- EPSS Score: %1.21
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38370
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.... Read more
Affected Products : alpine- EPSS Score: %0.19
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-38366
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.... Read more
Affected Products : sitecore- EPSS Score: %2.79
- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38365
Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a "Glowworm" attack.... Read more
- EPSS Score: %0.44
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024