|
197431
|
6.5 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vuln…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-20480
|
2024-11-21 14:46 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197432
|
7.8 |
HIGH
Local
|
mongodb
|
compass
|
A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This i…
|
CWE-269
Improper Privilege Management
|
CVE-2021-20334
|
2024-11-21 14:46 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197433
|
9.8 |
CRITICAL
Network
|
htmldoc_project debian
|
htmldoc debian_linux
|
Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.
|
-
|
CVE-2021-20308
|
2024-11-21 14:46 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197434
|
9.8 |
CRITICAL
Network
|
libpano13_project fedoraproject debian
|
libpano13 fedora debian_linux
|
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
|
-
|
CVE-2021-20307
|
2024-11-21 14:46 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197435
|
8.1 |
HIGH
Network
|
nettle_project redhat fedoraproject netapp debian
|
nettle enterprise_linux fedora ontap_select_deploy_administration_utility active_iq_unified_manager debian_linux
|
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply fun…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20305
|
2024-11-21 14:46 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197436
|
6.5 |
MEDIUM
Network
|
storage_project redhat fedoraproject
|
storage enterprise_linux openshift_container_platform fedora
|
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not…
|
-
|
CVE-2021-20291
|
2024-11-21 14:46 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197437
|
5.3 |
MEDIUM
Network
|
openexr debian
|
openexr debian_linux
|
A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could ca…
|
-
|
CVE-2021-20296
|
2024-11-21 14:46 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197438
|
8.1 |
HIGH
Network
|
zeromq
|
libzmq
|
There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sized changed, but the buffer would remain the same as it is a …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20235
|
2024-11-21 14:46 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197439
|
6.5 |
MEDIUM
Network
|
zeromq
|
libzmq
|
An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multiple malicious or comp…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-20234
|
2024-11-21 14:46 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197440
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_engineering_lifecycle_manager rational_team_concert engineering_workflow_management engineering_lifecycle_management engineering_insights engineering_requirements_quality_assi…
|
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20520
|
2024-11-21 14:46 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|