Latest CVE Feed
-
3.5
LOWCVE-2021-33595
A address bar spoofing vulnerability was discovered in Safe Browser for iOS. Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. A remote atta... Read more
Affected Products : safe- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-33594
An address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted a malicious URL, it appears like a legitimate one on the address bar, while the content comes from other domain and presented in a wi... Read more
Affected Products : safe- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-33593
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing.... Read more
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33592
NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function.... Read more
Affected Products : toolbar- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-33591
An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page.... Read more
Affected Products : comic_viewer- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33590
GattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c.... Read more
Affected Products : gattlib- Published: May. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33587
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.... Read more
- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33586
InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue.... Read more
- Published: May. 27, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-33583
REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.... Read more
Affected Products : timecard- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33582
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fix... Read more
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-33581
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idsscheer.ppmmashup.web.webservice.impl.ZP... Read more
Affected Products : mashzone_nextgen- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33580
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatica... Read more
Affected Products : roller- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33578
Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and ... Read more
Affected Products : sharecare- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-33577
An issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves (via encryption and signing of the message) can be bypassed by changing the Content-Type of the message to text/plain.... Read more
Affected Products : lexicom- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33576
An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.... Read more
Affected Products : lexicom- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33575
The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.... Read more
Affected Products : ruby-jss- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33574
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a de... Read more
Affected Products : fedora debian_linux solidfire_baseboard_management_controller_firmware cloud_backup e-series_santricity_os_controller h300s_firmware h500s_firmware h700s_firmware h410s_firmware glibc +10 more products- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-33572
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A ... Read more
Affected Products : cloud_protection_for_salesforce elements_for_microsoft_365 endpoint_protection linux_security- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33571
In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP ... Read more
- Published: Jun. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-33570
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading local files via vectors involving XMLHttpRequest and open of a file:/// URL, or discovering PostgreSQL passwords via ... Read more
Affected Products : postbird- Published: May. 25, 2021
- Modified: Nov. 21, 2024