|
196031
|
6.1 |
MEDIUM
Network
|
sonicwall
|
sonicos
|
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
|
CWE-601
Open Redirect
|
CVE-2021-20031
|
2024-11-21 14:45 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196032
|
7.2 |
HIGH
Network
|
telus
|
prv65b444a-s-ts_firmware
|
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A remote attacker co…
|
CWE-78
OS Command
|
CVE-2021-20122
|
2024-11-21 14:45 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196033
|
4.0 |
MEDIUM
Physics
|
telus
|
prv65b444a-s-ts_firmware
|
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary …
|
NVD-CWE-noinfo
|
CVE-2021-20121
|
2024-11-21 14:45 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196034
|
6.5 |
MEDIUM
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_400_firmware sma_410_firmware sma_500v
|
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
|
CWE-78
OS Command
|
CVE-2021-20035
|
2024-11-21 14:45 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196035
|
9.1 |
CRITICAL
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_400_firmware sma_410_firmware sma_500v
|
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to facto…
|
CWE-22
Path Traversal
|
CVE-2021-20034
|
2024-11-21 14:45 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196036
|
7.8 |
HIGH
Local
|
sonicwall
|
global_vpn_client
|
SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which potentially allows command execution in the host o…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-20037
|
2024-11-21 14:45 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196037
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8009w_firmware apq8053_firmware ar9380_firmware ipq8064_firmware ipq8065_firmware ipq8068_firmware ipq8069_firmware msm8909w_firmware msm8953_firmware qca6320_firmware
|
Use-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon W…
|
CWE-416
Use After Free
|
CVE-2021-1947
|
2024-11-21 14:45 |
2021-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196038
|
5.5 |
MEDIUM
Local
|
qualcomm
|
apq8009_firmware apq8009w_firmware apq8017_firmware apq8053_firmware aqt1000_firmware msm8909w_firmware msm8917_firmware msm8953_firmware qca4020_firmware qca6174a_firmware…
|
Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, …
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-1939
|
2024-11-21 14:45 |
2021-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196039
|
9.8 |
CRITICAL
Network
|
qualcomm
|
apq8009_firmware apq8009w_firmware apq8017_firmware apq8053_firmware apq8064au_firmware apq8096au_firmware aqt1000_firmware ar7420_firmware ar8031_firmware ar8035_firmware<…
|
A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon In…
|
CWE-416
Use After Free
|
CVE-2021-1976
|
2024-11-21 14:45 |
2021-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196040
|
6.7 |
MEDIUM
Local
|
tenable
|
nessus_agent
|
Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent …
|
NVD-CWE-noinfo
|
CVE-2021-20118
|
2024-11-21 14:45 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|