Latest CVE Feed
-
7.1
HIGHCVE-2021-31320
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::generateGradientColorTable function of their custom fork of the rlottie library. A remote attacker might be able to ov... Read more
Affected Products : telegram- EPSS Score: %0.26
- Published: May. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31319
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-... Read more
Affected Products : telegram- EPSS Score: %0.20
- Published: May. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31318
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function of their custom fork of the rlottie library. A remote attacker might be able to access heap memo... Read more
Affected Products : telegram- EPSS Score: %0.20
- Published: May. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31317
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's heap memory out-of-bou... Read more
Affected Products : telegram- EPSS Score: %0.20
- Published: May. 18, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-31316
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.... Read more
Affected Products : webpanel- EPSS Score: %65.42
- Published: May. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31315
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's stack memory out-of-bo... Read more
Affected Products : telegram- EPSS Score: %0.20
- Published: May. 18, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-31294
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to h... Read more
Affected Products : redis- EPSS Score: %0.21
- Published: Jul. 15, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-31292
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.... Read more
- EPSS Score: %0.46
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31274
In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description variable. As a result, arbitrary Javascript code can get executed.... Read more
Affected Products : librenms- EPSS Score: %0.01
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31272
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.... Read more
Affected Products : serenityos- EPSS Score: %1.07
- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31262
The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31261
The gf_hinter_track_new function in GPAC 1.0.1 allows attackers to read memory via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- EPSS Score: %0.13
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31260
The MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31259
The gf_isom_cenc_get_default_info_internal function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31258
The gf_isom_set_extraction_slc function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31257
The HintFile function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.... Read more
Affected Products : gpac- EPSS Score: %0.10
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31256
Memory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.... Read more
Affected Products : gpac- EPSS Score: %0.13
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-31255
Buffer overflow in the abst_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.... Read more
Affected Products : gpac- EPSS Score: %0.42
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-31254
Buffer overflow in the tenc_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file, related invalid IV sizes.... Read more
Affected Products : gpac- EPSS Score: %0.42
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-31252
An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it.... Read more
Affected Products : bf-430_firmware bf-431_firmware bf-450m_firmware semac_s2_firmware semac_d1_firmware semac_d2_firmware semac_d4_firmware semac_s3v3_firmware semac_d2_n300_firmware semac_s1_osdp_firmware +18 more products- EPSS Score: %2.87
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024