|
196181
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-22254
|
2024-11-21 14:49 |
2021-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196182
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-22246
|
2024-11-21 14:49 |
2021-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196183
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.
|
CWE-79
Cross-site Scripting
|
CVE-2021-22238
|
2024-11-21 14:49 |
2021-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196184
|
7.5 |
HIGH
Network
|
komoot
|
komoot
|
An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially crafted series of network requests can lead to the disclosu…
|
CWE-200
Information Exposure
|
CVE-2021-21823
|
2024-11-21 14:49 |
2021-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196185
|
7.8 |
HIGH
Local
|
codesys
|
codesys
|
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted f…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-21868
|
2024-11-21 14:49 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196186
|
7.8 |
HIGH
Local
|
codesys
|
codesys
|
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafte…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-21867
|
2024-11-21 14:49 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196187
|
8.8 |
HIGH
Network
|
gpac
|
gpac
|
Multiple exploitable integer truncation vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cau…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-21862
|
2024-11-21 14:49 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196188
|
8.8 |
HIGH
Network
|
gpac debian
|
gpac debian_linux
|
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-21858
|
2024-11-21 14:49 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196189
|
8.8 |
HIGH
Network
|
gpac debian
|
gpac debian_linux
|
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-21857
|
2024-11-21 14:49 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196190
|
8.8 |
HIGH
Network
|
gpac
|
gpac
|
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-21856
|
2024-11-21 14:49 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|