|
197781
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_central apex_one cloud_edge deep_security control_manager deep_discovery_analyzer deep_discovery_email_inspector deep_discovery_inspector interscan_messaging_security_vir…
|
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by a…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-25252
|
2024-11-21 14:54 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197782
|
7.8 |
HIGH
Local
|
saltstack
|
salt
|
CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify…
|
-
|
CVE-2021-25315
|
2024-11-21 14:54 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197783
|
7.5 |
HIGH
Network
|
google
|
android
|
Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider.
|
NVD-CWE-noinfo
|
CVE-2021-25330
|
2024-11-21 14:54 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197784
|
9.8 |
CRITICAL
Network
|
gigaset
|
dx600a_firmware
|
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password p…
|
CWE-307 CWE-521
mproper Restriction of Excessive Authentication Attempts Weak Password Requirements
|
CVE-2021-25309
|
2024-11-21 14:54 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197785
|
7.5 |
HIGH
Network
|
gigaset
|
dx600a_firmware
|
A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-25306
|
2024-11-21 14:54 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197786
|
7.0 |
HIGH
Local
|
apache debian oracle
|
tomcat debian_linux managed_file_transfer instantis_enterprisetrack agile_plm database siebel_ui_framework mysql_enterprise_monitor graph_server_and_client communications_c…
|
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikel…
|
NVD-CWE-noinfo
|
CVE-2021-25329
|
2024-11-21 14:54 |
2021-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197787
|
7.5 |
HIGH
Network
|
apache debian oracle
|
tomcat debian_linux managed_file_transfer instantis_enterprisetrack agile_plm database siebel_ui_framework mysql_enterprise_monitor graph_server_and_client communications_c…
|
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body…
|
CWE-200
Information Exposure
|
CVE-2021-25122
|
2024-11-21 14:54 |
2021-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197788
|
4.4 |
MEDIUM
Local
|
saltstack fedoraproject debian
|
salt fedora debian_linux
|
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
|
CWE-532 CWE-522
Inclusion of Sensitive Information in Log Files Insufficiently Protected Credentials
|
CVE-2021-25284
|
2024-11-21 14:54 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197789
|
9.8 |
CRITICAL
Network
|
saltstack fedoraproject debian
|
salt fedora debian_linux
|
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
|
CWE-94
Code Injection
|
CVE-2021-25283
|
2024-11-21 14:54 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197790
|
9.1 |
CRITICAL
Network
|
saltstack fedoraproject debian
|
salt fedora debian_linux
|
An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.
|
CWE-22
Path Traversal
|
CVE-2021-25282
|
2024-11-21 14:54 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|