|
197551
|
7.5 |
HIGH
Network
|
qualcomm
|
apq8009w_firmware apq8017_firmware apq8053_firmware apq8064au_firmware apq8096au_firmware aqt1000_firmware msm8909w_firmware msm8917_firmware msm8937_firmware msm8953_firmw…
|
Null pointer dereference can occur due to lack of null check for user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IO…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-1936
|
2024-11-21 14:45 |
2021-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197552
|
8.4 |
HIGH
Local
|
qualcomm
|
aqt1000_firmware ar8035_firmware qca6390_firmware qca6420_firmware qca6430_firmware qca6574a_firmware qca6574au_firmware qca6595_firmware qca6595au_firmware qca6696_firmwar…
|
Improper access control in trusted application environment can cause unauthorized access to CDSP or ADSP VM memory with either privilege in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit…
|
NVD-CWE-Other
|
CVE-2021-1932
|
2024-11-21 14:45 |
2021-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197553
|
8.4 |
HIGH
Local
|
qualcomm
|
apq8017_firmware apq8053_firmware aqt1000_firmware msm8917_firmware msm8953_firmware qca6174a_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6430_firmware
|
Null pointer dereference can occur due to memory allocation failure in DIAG in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Wearables
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-1917
|
2024-11-21 14:45 |
2021-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197554
|
8.4 |
HIGH
Local
|
qualcomm
|
aqt1000_firmware ar8035_firmware csrb31024_firmware qca6174a_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6421_firmware qca6426_firmware qca6430_firmware<…
|
Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdra…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-1913
|
2024-11-21 14:45 |
2021-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197555
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_admanager_plus
|
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20131
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197556
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_admanager_plus
|
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20130
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197557
|
7.5 |
HIGH
Network
|
draytek
|
vigorconnect
|
An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-20129
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197558
|
5.4 |
MEDIUM
Network
|
draytek
|
vigorconnect
|
The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20128
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197559
|
8.1 |
HIGH
Network
|
draytek
|
vigorconnect
|
An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete…
|
NVD-CWE-noinfo
|
CVE-2021-20127
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197560
|
8.8 |
HIGH
Network
|
draytek
|
vigorconnect
|
Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who…
|
CWE-352
Origin Validation Error
|
CVE-2021-20126
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|