|
194231
|
7.8 |
HIGH
Local
|
ibm
|
spectrum_protect_client spectrum_protect_for_space_management
|
IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processing the current locale settings. A local attacker c…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-29672
|
2024-11-21 15:01 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194232
|
2.5 |
LOW
Local
|
exiv2 fedoraproject debian
|
exiv2 fedora debian_linux
|
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv…
|
-
|
CVE-2021-29473
|
2024-11-21 15:01 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194233
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject
|
exiv2 fedora
|
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The o…
|
-
|
CVE-2021-29470
|
2024-11-21 15:01 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194234
|
7.5 |
HIGH
Network
|
redis.js
|
redis
|
Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings…
|
NVD-CWE-Other
|
CVE-2021-29469
|
2024-11-21 15:01 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194235
|
7.5 |
HIGH
Network
|
hashicorp
|
vault
|
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2021-29653
|
2024-11-21 15:01 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194236
|
7.5 |
HIGH
Network
|
discord
|
discord-recon
|
Discord-Recon is a bot for the Discord chat service. In versions of Discord-Recon 0.0.3 and prior, a remote attacker is able to read local files from the server that can disclose important informatio…
|
CWE-22
Path Traversal
|
CVE-2021-29466
|
2024-11-21 15:01 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194237
|
6.1 |
MEDIUM
Network
|
wrongthink_project
|
wrongthink
|
Wrongthink is an encrypted peer-to-peer chat program. A user could check their fingerprint into the service and enter a script to run arbitrary JavaScript on the site. No workarounds exist, but a pat…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29467
|
2024-11-21 15:01 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194238
|
9.8 |
CRITICAL
Network
|
pupnp_project
|
pupnp
|
The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-29462
|
2024-11-21 15:01 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194239
|
6.1 |
MEDIUM
Network
|
xmbforum2
|
xmb
|
XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.1…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29399
|
2024-11-21 15:01 |
2021-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194240
|
6.5 |
MEDIUM
Network
|
curveballjs
|
a12n-server
|
a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to…
|
CWE-863
Incorrect Authorization
|
CVE-2021-29452
|
2024-11-21 15:01 |
2021-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|