|
196341
|
6.5 |
MEDIUM
Local
|
vmware
|
workstation horizon_client
|
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious act…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-21989
|
2024-11-21 14:49 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196342
|
6.5 |
MEDIUM
Local
|
vmware
|
workstation horizon_client
|
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (JPEG2000 Parser). A maliciou…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-21988
|
2024-11-21 14:49 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196343
|
6.5 |
MEDIUM
Local
|
vmware
|
workstation horizon_client
|
VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious act…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-21987
|
2024-11-21 14:49 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196344
|
6.5 |
MEDIUM
Network
|
huawei
|
manageone
|
There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-22339
|
2024-11-21 14:49 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196345
|
7.8 |
HIGH
Local
|
vmware
|
rabbitmq
|
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-22117
|
2024-11-21 14:49 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196346
|
7.5 |
HIGH
Network
|
elastic
|
elastic_app_search
|
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta feature. Using this vector, an attacker whose websit…
|
CWE-611
XXE
|
CVE-2021-22140
|
2024-11-21 14:49 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196347
|
6.5 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to creat…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-22139
|
2024-11-21 14:49 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196348
|
3.7 |
LOW
Network
|
elastic
|
logstash
|
In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When specifying a trusted server CA certificate Logstash would not…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-22138
|
2024-11-21 14:49 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196349
|
5.3 |
MEDIUM
Network
|
elastic
|
elasticsearch
|
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions whe…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2021-22137
|
2024-11-21 14:49 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196350
|
3.5 |
LOW
Physics
|
elastic
|
kibana
|
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background pol…
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-22136
|
2024-11-21 14:49 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|