|
196481
|
9.8 |
CRITICAL
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-21748
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196482
|
4.3 |
MEDIUM
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a reque…
|
CWE-352
Origin Validation Error
|
CVE-2021-21745
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196483
|
7.5 |
HIGH
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of the device, causing some security functions of th…
|
NVD-CWE-noinfo
|
CVE-2021-21744
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196484
|
4.3 |
MEDIUM
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.
|
CWE-74
Injection
|
CVE-2021-21743
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196485
|
6.1 |
MEDIUM
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.
|
CWE-79
Cross-site Scripting
|
CVE-2021-21747
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196486
|
6.1 |
MEDIUM
Network
|
zte
|
mf971r_firmware
|
ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie information.
|
CWE-79
Cross-site Scripting
|
CVE-2021-21746
|
2024-11-21 14:48 |
2021-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196487
|
7.8 |
HIGH
Local
|
gonitro
|
nitro_pro
|
An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different…
|
CWE-415
Double Free
|
CVE-2021-21797
|
2024-11-21 14:48 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196488
|
7.8 |
HIGH
Local
|
gonitro
|
nitro_pro
|
An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroye…
|
CWE-416
Use After Free
|
CVE-2021-21796
|
2024-11-21 14:48 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196489
|
6.1 |
MEDIUM
Network
|
jenkins
|
git
|
Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripti…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-21684
|
2024-11-21 14:48 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196490
|
6.5 |
MEDIUM
Network
|
jenkins
|
jenkins
|
The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Ov…
|
CWE-22
Path Traversal
|
CVE-2021-21683
|
2024-11-21 14:48 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|