Latest CVE Feed
-
7.8
HIGHCVE-2021-22556
The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pages that they don’t own, allowing them to control kernel memory from userspace. We recommend upgrading to k... Read more
Affected Products : fuchsia- EPSS Score: %0.02
- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2021-22555
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space... Read more
Affected Products : linux_kernel hci_management_node solidfire h615c_firmware h610s_firmware h610c_firmware fas_8300_firmware fas_8700_firmware aff_a400_firmware fabric_operating_system +10 more products- EPSS Score: %82.42
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22553
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recom... Read more
Affected Products : gerrit- EPSS Score: %0.15
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22552
An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory from within the ... Read more
Affected Products : asylo- EPSS Score: %0.02
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22550
An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https://github.com/google/asylo/commit/a47ef55db2337d29de19c50cd29b0deb2871d31c... Read more
Affected Products : asylo- EPSS Score: %0.02
- Published: Jun. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22549
An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended to update past 0.6.2 or git commit https://github.com/google/asylo/commit/53ed5d8fd8118ced1466e509606dd2f473707a5c... Read more
Affected Products : asylo- EPSS Score: %0.02
- Published: Jun. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22548
An attacker can change the pointer to untrusted memory to point to trusted memory region which causes copying trusted memory to trusted memory, if the latter is later copied out, it allows for reading of memory regions from the trusted region. It is recom... Read more
Affected Products : asylo- EPSS Score: %0.02
- Published: Jun. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22547
In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowing the attacker access to the other ... Read more
Affected Products : cloud_iot_device_sdk_for_embedded_c- EPSS Score: %0.03
- Published: May. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22545
An attacker can craft a specific IdaPro *.i64 file that will cause the BinDiff plugin to load an invalid memory offset. This can allow the attacker to control the instruction pointer and execute arbitrary code. It is recommended to upgrade BinDiff 7... Read more
Affected Products : bindiff- EPSS Score: %0.06
- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2021-22543
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM... Read more
Affected Products : linux_kernel fedora debian_linux solidfire_baseboard_management_controller_firmware h410c_firmware cloud_backup h300s_firmware h500s_firmware h700s_firmware h410s_firmware +11 more products- EPSS Score: %0.00
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22540
Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering. The validation logic in dart:html for creating DOM nodes from text did not sanitize properly when it came across template tags.... Read more
Affected Products : dart_software_development_kit- EPSS Score: %0.36
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-22539
An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel allows the workspace path to lint *.bzl files to be set via this config file. As such the attacker is able to execute any executable on ... Read more
Affected Products : bazel- EPSS Score: %0.08
- Published: Apr. 16, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22538
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create... Read more
Affected Products : exposure_notifications_verification_server- EPSS Score: %0.24
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-22535
Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure.... Read more
Affected Products : netiq_directory_and_resource_administrator- EPSS Score: %0.23
- Published: Sep. 28, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22531
A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0... Read more
Affected Products : access_manager- EPSS Score: %0.23
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-22528
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4... Read more
- EPSS Score: %0.36
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22527
Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4... Read more
- EPSS Score: %0.32
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22526
Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4... Read more
- EPSS Score: %0.14
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22525
This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1... Read more
Affected Products : access_manager- EPSS Score: %0.05
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-22524
Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4... Read more
- EPSS Score: %0.20
- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024