|
197191
|
9.6 |
CRITICAL
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craft…
|
CWE-416
Use After Free
|
CVE-2021-21107
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197192
|
9.6 |
CRITICAL
Network
|
google fedoraproject debian
|
chrome fedora debian_linux
|
Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2021-21106
|
2024-11-21 14:47 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197193
|
5.5 |
MEDIUM
Local
|
courtbouillon
|
cairosvg
|
CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When process…
|
-
|
CVE-2021-21236
|
2024-11-21 14:47 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197194
|
6.5 |
MEDIUM
Network
|
kamadak-exif_project
|
kamadak-exif
|
kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop in parsing crafted PNG files. Specifically, reader::read_from_container can caus…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-21235
|
2024-11-21 14:47 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197195
|
7.7 |
HIGH
Network
|
spring-boot-actuator-logview_project
|
spring-boot-actuator-logview
|
spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is maven package "eu.hinsch:spring-boot-actuator-logview". In spring-boot-actuator-log…
|
-
|
CVE-2021-21234
|
2024-11-21 14:47 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197196
|
- |
|
-
|
-
|
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or …
|
-
|
CVE-2021-20451
|
2024-11-21 14:46 |
2024-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197197
|
- |
|
-
|
-
|
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
|
-
|
CVE-2021-20556
|
2024-11-21 14:46 |
2024-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197198
|
- |
|
-
|
-
|
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link…
|
-
|
CVE-2021-20450
|
2024-11-21 14:46 |
2024-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197199
|
4.3 |
MEDIUM
Network
|
ibm
|
security_verify_privilege_on-premises
|
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324.
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-20581
|
2024-11-21 14:46 |
2023-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197200
|
5.9 |
MEDIUM
Network
|
samba fedoraproject
|
samba fedora
|
A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.
|
CWE-362
Race Condition
|
CVE-2021-20251
|
2024-11-21 14:46 |
2023-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|