Latest CVE Feed
-
7.8
HIGHCVE-2021-21813
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to memcpy copying the path provided by the user into a staticly sized buffer without any length ... Read more
Affected Products : xmill- EPSS Score: %0.06
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-21812
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7. Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command l... Read more
Affected Products : xmill- EPSS Score: %0.06
- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21811
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : xmill- EPSS Score: %0.59
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21810
A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : xmill- EPSS Score: %0.59
- Published: Aug. 17, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-21809
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.... Read more
Affected Products : moodle- EPSS Score: %68.50
- Published: Jun. 23, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21808
A memory corruption vulnerability exists in the PNG png_palette_process functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide malicious inputs to trigger this vulnerability... Read more
Affected Products : imagegear- EPSS Score: %0.42
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21807
An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a stack-based buffer overflow. An attacker can provide a malicious file to trigger this vu... Read more
Affected Products : imagegear- EPSS Score: %0.46
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21806
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in remote code execution. The victim needs to visit a malicious web site to trigg... Read more
Affected Products : webkitgtk- EPSS Score: %1.60
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-21805
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can send a crafted HTTP request to trig... Read more
Affected Products : r-seenet- EPSS Score: %92.43
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21804
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacker can send a crafted HTTP request t... Read more
Affected Products : r-seenet- EPSS Score: %27.81
- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21803
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.... Read more
Affected Products : r-seenet- EPSS Score: %73.89
- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21802
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.... Read more
Affected Products : r-seenet- EPSS Score: %75.25
- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21801
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.... Read more
Affected Products : r-seenet- EPSS Score: %85.20
- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21800
Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted us... Read more
Affected Products : r-seenet- EPSS Score: %72.46
- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-21799
Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted... Read more
Affected Products : r-seenet- EPSS Score: %75.98
- Published: Jul. 16, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21798
An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, resulting in the application dereferencing a stale pointer.... Read more
Affected Products : nitro_pro- EPSS Score: %40.26
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21797
An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When closed, the document will result in the re... Read more
Affected Products : nitro_pro- EPSS Score: %71.71
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21796
An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later reused, resulting in a use-after-free v... Read more
Affected Products : nitro_pro- EPSS Score: %75.47
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21795
A heap-based buffer overflow vulnerability exists in the PSD read_icc_icCurve_data functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an integer overflow that, in turn, leads to a heap buffer overflow. An attacker can... Read more
Affected Products : imagegear- EPSS Score: %0.46
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21794
An out-of-bounds write vulnerability exists in the TIF bits_per_sample processing functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerab... Read more
Affected Products : imagegear- EPSS Score: %0.32
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024