|
197751
|
2.4 |
LOW
Physics
|
samsung
|
account
|
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
|
NVD-CWE-Other
|
CVE-2021-25351
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197752
|
3.9 |
LOW
Physics
|
samsung
|
account
|
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-25350
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197753
|
7.8 |
HIGH
Local
|
samsung
|
slow_motion_editor
|
Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
|
NVD-CWE-Other
|
CVE-2021-25349
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197754
|
8.8 |
HIGH
Network
|
sophos
|
connect
|
A malicious website could execute code remotely in Sophos Connect Client before version 2.1.
|
NVD-CWE-noinfo
|
CVE-2021-25265
|
2024-11-21 14:54 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197755
|
4.8 |
MEDIUM
Network
|
ftapi
|
ftapi
|
FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template Editor.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25278
|
2024-11-21 14:54 |
2021-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197756
|
6.1 |
MEDIUM
Network
|
ftapi
|
ftapi
|
FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25277
|
2024-11-21 14:54 |
2021-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197757
|
7.5 |
HIGH
Network
|
python
|
pillow
|
An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2021-25293
|
2024-11-21 14:54 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197758
|
6.5 |
MEDIUM
Network
|
python
|
pillow
|
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2021-25292
|
2024-11-21 14:54 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197759
|
7.5 |
HIGH
Network
|
python
|
pillow
|
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
|
CWE-125
Out-of-bounds Read
|
CVE-2021-25291
|
2024-11-21 14:54 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197760
|
7.5 |
HIGH
Network
|
python debian
|
pillow debian_linux
|
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25290
|
2024-11-21 14:54 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|