|
194201
|
7.5 |
HIGH
Network
|
mintty_project
|
mintty
|
Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results in many SetWindowTex…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-28848
|
2024-11-21 15:00 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194202
|
7.5 |
HIGH
Network
|
mobatek
|
mobaxterm
|
MobaXterm before 21.0 allows remote servers to cause a denial of service (Windows GUI hang) via tab title change requests that are sent repeatedly at high speed, which results in many SetWindowTextA …
|
NVD-CWE-noinfo
|
CVE-2021-28847
|
2024-11-21 15:00 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194203
|
8.8 |
HIGH
Network
|
qnap
|
video_station
|
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue aff…
|
CWE-77
Command Injection
|
CVE-2021-28812
|
2024-11-21 15:00 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194204
|
5.4 |
MEDIUM
Network
|
qnap
|
q\'center
|
A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have a…
|
-
|
CVE-2021-28807
|
2024-11-21 15:00 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194205
|
5.4 |
MEDIUM
Network
|
qnap
|
qts quts_hero qutscloud
|
A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Syst…
|
-
|
CVE-2021-28806
|
2024-11-21 15:00 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194206
|
5.5 |
MEDIUM
Local
|
python fedoraproject
|
pillow fedora
|
An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decode…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-28678
|
2024-11-21 15:00 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194207
|
7.5 |
HIGH
Network
|
python fedoraproject
|
pillow fedora
|
An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally q…
|
NVD-CWE-noinfo
|
CVE-2021-28677
|
2024-11-21 15:00 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194208
|
7.5 |
HIGH
Network
|
python fedoraproject
|
pillow fedora
|
An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-28676
|
2024-11-21 15:00 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194209
|
5.5 |
MEDIUM
Local
|
python fedoraproject
|
pillow fedora
|
An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input layers relative to the size of the data block. This could lead to a DoS on Ima…
|
CWE-252
Unchecked Return Value
|
CVE-2021-28675
|
2024-11-21 15:00 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194210
|
9.8 |
CRITICAL
Network
|
synology
|
photo_station
|
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to…
|
-
|
CVE-2021-29089
|
2024-11-21 15:00 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|