Latest CVE Feed
-
9.8
CRITICALCVE-2021-21795
A heap-based buffer overflow vulnerability exists in the PSD read_icc_icCurve_data functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an integer overflow that, in turn, leads to a heap buffer overflow. An attacker can... Read more
Affected Products : imagegear- EPSS Score: %0.46
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21794
An out-of-bounds write vulnerability exists in the TIF bits_per_sample processing functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerab... Read more
Affected Products : imagegear- EPSS Score: %0.32
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21793
An out-of-bounds write vulnerability exists in the JPG sof_nb_comp header processing functionality of Accusoft ImageGear 19.8 and 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger t... Read more
Affected Products : imagegear- EPSS Score: %0.42
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21792
An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver w... Read more
Affected Products : advanced_systemcare_ultimate- EPSS Score: %0.06
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21791
An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver w... Read more
Affected Products : advanced_systemcare_ultimate- EPSS Score: %0.06
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21790
An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver w... Read more
Affected Products : advanced_systemcare_ultimate- EPSS Score: %0.06
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21789
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0e0, the first dword passed in the input buffer is the device port to write to and the d... Read more
Affected Products : advanced_systemcare_ultimate- EPSS Score: %0.05
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21788
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0dc, the first dword passed in the input buffer is the device port to write to and the w... Read more
Affected Products : advanced_systemcare_ultimate- EPSS Score: %0.05
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21787
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0d8, the first dword passed in the input buffer is the device port to write to and the b... Read more
Affected Products : advanced_systemcare_ultimate- EPSS Score: %0.06
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21786
A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to increased privileges. An attacker can send a malicious IRP to trigger t... Read more
Affected Products : advanced_systemcare_ultimate- EPSS Score: %0.05
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21785
An information disclosure vulnerability exists in the IOCTL 0x9c40a148 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to a disclosure of sensitive information. An attacker can send a malici... Read more
Affected Products : advanced_systemcare_ultimate- EPSS Score: %0.05
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21784
An out-of-bounds write vulnerability exists in the JPG format SOF marker processing of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : imagegear- EPSS Score: %0.40
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21783
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.... Read more
- EPSS Score: %0.56
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21782
An out-of-bounds write vulnerability exists in the SGI format buffer size processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulne... Read more
Affected Products : imagegear- EPSS Score: %0.40
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-21781
An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak ke... Read more
- EPSS Score: %0.02
- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21779
A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiti... Read more
- EPSS Score: %0.15
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21778
A denial of service vulnerability exists in the ASDU message processing functionality of MZ Automation GmbH lib60870.NET 2.2.0. A specially crafted network request can lead to loss of communications. An attacker can send an unauthenticated message to trig... Read more
Affected Products : lib60870- EPSS Score: %0.53
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-21777
An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead to an out-of-bounds read.... Read more
Affected Products : opener- EPSS Score: %0.44
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21776
An out-of-bounds write vulnerability exists in the SGI Format Buffer Size Processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulne... Read more
Affected Products : imagegear- EPSS Score: %0.40
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-21775
A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the ... Read more
- EPSS Score: %0.19
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024