|
194061
|
7.2 |
HIGH
Network
|
meritlilin
|
p2r8852e2_firmware p2r8852e4_firmware p2r6852e2_firmware p2r6852e4_firmware p2r6552e2_firmware p2r6552e4_firmware p2r6352ae2_firmware p2r6352ae4_firmware p2r3052ae2_firmware
|
The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after log…
|
-
|
CVE-2021-30166
|
2024-11-21 15:03 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194062
|
9.8 |
CRITICAL
Network
|
apache
|
ofbiz
|
Apache OFBiz has unsafe deserialization prior to 17.12.07 version
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-30128
|
2024-11-21 15:03 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194063
|
8.1 |
HIGH
Network
|
edimax
|
ic-3140w_firmware
|
The default administrator account & password of the EDIMAX wireless network camera is hard-coded. Remote attackers can disassemble firmware to obtain the privileged permission and further control the…
|
-
|
CVE-2021-30165
|
2024-11-21 15:03 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194064
|
8.1 |
HIGH
Network
|
checkpoint
|
identity_agent
|
A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.
|
NVD-CWE-noinfo
|
CVE-2021-30356
|
2024-11-21 15:03 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194065
|
9.8 |
CRITICAL
Network
|
hashicorp
|
terraform_provider
|
HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Vault’s GCP auth method. Fixed in 2.19.1.
|
NVD-CWE-noinfo
|
CVE-2021-30476
|
2024-11-21 15:03 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194066
|
7.5 |
HIGH
Network
|
alpinelinux
|
apk-tools
|
In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash.
|
CWE-125
Out-of-bounds Read
|
CVE-2021-30139
|
2024-11-21 15:03 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194067
|
7.5 |
HIGH
Network
|
omicronenergy
|
stationguard
|
OMICRON StationGuard before 1.10 allows remote attackers to cause a denial of service (connectivity outage) via crafted tcp/20499 packets to the CTRL Ethernet port.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-30464
|
2024-11-21 15:03 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194068
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gf_filter_pck_get_data is called. The first arg pck may be null with a crafted mp4 file,which results in a crash.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-30199
|
2024-11-21 15:03 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194069
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers.c in GPAC 1.0.1 there is a loop, which with crafted file, pps->num_tile_columns may be larger than sizeof(pps->column_w…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-30020
|
2024-11-21 15:03 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194070
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
In the adts_dmx_process function in filters/reframe_adts.c in GPAC 1.0.1, a crafted file may cause ctx->hdr.frame_size to be smaller than ctx->hdr.hdr_size, resulting in size to be a negative number …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-30019
|
2024-11-21 15:03 |
2021-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|