Latest CVE Feed
-
10.0
HIGHCVE-2021-38390
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egy... Read more
Affected Products : diaenergie- EPSS Score: %1.65
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38389
Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.... Read more
Affected Products : webaccess- EPSS Score: %1.06
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38387
In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and waiting forever, which may cause excessive CPU consumption.... Read more
- EPSS Score: %0.33
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38386
In Contiki 3.0, a buffer overflow in the Telnet service allows remote attackers to cause a denial of service because the ls command is mishandled when a directory has many files with long names.... Read more
- EPSS Score: %0.60
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38385
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.... Read more
Affected Products : tor- EPSS Score: %0.63
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38384
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status co... Read more
Affected Products : serverless_offline- EPSS Score: %0.33
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38383
OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c.... Read more
Affected Products : owntone- EPSS Score: %0.42
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-38382
Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.... Read more
- EPSS Score: %0.22
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-38381
Live555 through 1.08 does not handle MPEG-1 or 2 files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.... Read more
- EPSS Score: %0.22
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38380
Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An attacker can leverage this to launch a DoS attack.... Read more
- EPSS Score: %0.28
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38379
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.... Read more
Affected Products : cfengine- EPSS Score: %0.03
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38378
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.... Read more
- EPSS Score: %0.25
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38377
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.... Read more
- EPSS Score: %0.30
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-38376
OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.... Read more
- EPSS Score: %0.27
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38375
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.... Read more
- EPSS Score: %0.34
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38374
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.... Read more
- EPSS Score: %0.38
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-38373
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.... Read more
Affected Products : kmail- EPSS Score: %0.16
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38372
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.... Read more
- EPSS Score: %0.31
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38371
The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.... Read more
Affected Products : exim- EPSS Score: %1.21
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-38370
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.... Read more
Affected Products : alpine- EPSS Score: %0.19
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024