Latest CVE Feed
-
6.1
MEDIUMCVE-2021-32569
In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross-Site Scripting. This problem is completely resolved in new Ericsson library browsing tool ELEX used in systems like Ericsson Network M... Read more
- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32568
mrdoc is vulnerable to Deserialization of Untrusted Data... Read more
Affected Products : mrdoc- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32567
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.... Read more
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32566
Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.... Read more
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32565
Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.... Read more
- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32563
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve cod... Read more
Affected Products : thunar- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-32561
OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.... Read more
Affected Products : octoprint- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-32560
The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.... Read more
Affected Products : octoprint- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32558
An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media fo... Read more
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-32557
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.... Read more
Affected Products : apport- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2021-32556
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.... Read more
Affected Products : apport- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-32555
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local users.... Read more
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-32554
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users.... Read more
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-32553
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.... Read more
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-32552
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.... Read more
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-32551
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could expose private data to other local users.... Read more
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-32550
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users.... Read more
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-32549
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users.... Read more
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-32548
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users.... Read more
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-32547
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.... Read more
- Published: Jun. 12, 2021
- Modified: Nov. 21, 2024