Latest CVE Feed
-
9.1
CRITICALCVE-2021-23921
An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements.... Read more
Affected Products : devolutions_server- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23910
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is an out-of-bounds array access in RemoteDiagnosisApp.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23909
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MCU allows remote code execution.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23908
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A type confusion issue affects MultiSvSetAttributes in the HiQnet Protocol, leading to remote code execution.... Read more
Affected Products : headunit_ntg6_mercedes-benz_user_experience a_220 a_220_4matic e_350 e_350_4matic eqc gle_350 gle_350_4matic- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23907
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet Protocol, leading to remote code execution.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-23906
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A Message Length is not checked in the HiQnet Protocol, leading to remote code execution.... Read more
Affected Products : mercedes-benz_user_experience a_220 a_220_4matic e_350 e_350_4matic eqc gle_350 gle_350_4matic- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-23901
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfer... Read more
- Published: Jan. 25, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23900
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these situations.... Read more
Affected Products : json-sanitizer- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23899
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.... Read more
Affected Products : json-sanitizer- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
4.5
MEDIUMCVE-2021-23896
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the... Read more
Affected Products : database_security- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2021-23895
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized... Read more
Affected Products : database_security- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-23894
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serializ... Read more
Affected Products : database_security- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-23893
Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer.... Read more
Affected Products : drive_encryption- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-23892
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator pr... Read more
Affected Products : endpoint_security_for_linux_threat_prevention- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23891
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating a client token which could lead to the bypassing of MTP self-defense.... Read more
Affected Products : total_protection- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23890
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages (specifically McAfee Agent) available in ePO repository and install them on... Read more
Affected Products : epolicy_orchestrator- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-23889
Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.... Read more
Affected Products : epolicy_orchestrator- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-23888
Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal information from the authenticated user.... Read more
Affected Products : epolicy_orchestrator- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-23887
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspendi... Read more
- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-23886
Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is tr... Read more
- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024