|
194211
|
6.5 |
MEDIUM
Network
|
genivi
|
diagnostic_log_and_trace
|
GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special characters could cause a vul…
|
NVD-CWE-noinfo
|
CVE-2021-29507
|
2024-11-21 15:01 |
2021-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194212
|
8.8 |
HIGH
Network
|
xstream_project debian fedoraproject netapp oracle
|
xstream debian_linux fedora snapmanager webcenter_portal webcenter_sites communications_unified_inventory_management enterprise_manager_ops_center banking_credit_facilities_pr…
|
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of th…
|
-
|
CVE-2021-29505
|
2024-11-21 15:01 |
2021-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194213
|
8.3 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path wi…
|
-
|
CVE-2021-29492
|
2024-11-21 15:01 |
2021-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194214
|
7.5 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE before p7, and 11.4-RELEASE before p10, missing messag…
|
CWE-20
Improper Input Validation
|
CVE-2021-29629
|
2024-11-21 15:01 |
2021-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194215
|
7.5 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call triggering a fault could cause SMAP protections to be…
|
CWE-863
Incorrect Authorization
|
CVE-2021-29628
|
2024-11-21 15:01 |
2021-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194216
|
6.7 |
MEDIUM
Local
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate their privileges. IBM X-Force ID: 200883.
|
NVD-CWE-noinfo
|
CVE-2021-29708
|
2024-11-21 15:01 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194217
|
6.5 |
MEDIUM
Network
|
ibm
|
8335-gca_firmware 8335-gta_firmware 8335-gtb_firmware
|
IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request that would allow them to delete arbi…
|
CWE-22
Path Traversal
|
CVE-2021-29695
|
2024-11-21 15:01 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194218
|
5.3 |
MEDIUM
Network
|
ibm
|
infosphere_information_server
|
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against th…
|
NVD-CWE-noinfo
|
CVE-2021-29681
|
2024-11-21 15:01 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194219
|
5.5 |
MEDIUM
Local
|
nordicsemi
|
nrf52840_firmware
|
The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2021-29415
|
2024-11-21 15:01 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194220
|
6.1 |
MEDIUM
Physics
|
st
|
stm32cubel4_firmware
|
STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.
|
CWE-74
Injection
|
CVE-2021-29414
|
2024-11-21 15:01 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|