|
197731
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8009_firmware apq8009w_firmware apq8017_firmware apq8053_firmware apq8064au_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware ar8151_firmware<…
|
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snap…
|
CWE-416
Use After Free
|
CVE-2021-1905
|
2024-11-21 14:45 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197732
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8009w_firmware apq8017_firmware apq8053_firmware aqt1000_firmware ar8031_firmware ar8035_firmware ar9380_firmware csr8811_firmware csra6620_firmware csra6640_firmware
|
A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdr…
|
CWE-416
Use After Free
|
CVE-2021-1891
|
2024-11-21 14:45 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197733
|
7.5 |
HIGH
Network
|
buffalo
|
wsr-2533dhpl2-bk_firmware wsr-2533dhp3-bk_firmware
|
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.
|
CWE-287
Improper Authentication
|
CVE-2021-20092
|
2024-11-21 14:45 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197734
|
8.8 |
HIGH
Network
|
buffalo
|
wsr-2533dhpl2-bk_firmware wsr-2533dhp3-bk_firmware
|
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker could leverage thi…
|
NVD-CWE-noinfo
|
CVE-2021-20091
|
2024-11-21 14:45 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197735
|
9.8 |
CRITICAL
Network
|
buffalo
|
wsr-2533dhpl2-bk_firmware wsr-2533dhp3-bk_firmware
|
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass…
|
CWE-22
Path Traversal
|
CVE-2021-20090
|
2024-11-21 14:45 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197736
|
8.8 |
HIGH
Network
|
purl_project
|
purl
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20089
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197737
|
8.8 |
HIGH
Network
|
jquery-bbq_project
|
jquery-bbq
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20086
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197738
|
8.8 |
HIGH
Network
|
backbone-query-parameters_project
|
backbone-query-parameters
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20085
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197739
|
8.8 |
HIGH
Network
|
jquery-plugin-query-object_project
|
jquery-plugin-query-object
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20083
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197740
|
8.8 |
HIGH
Network
|
mootools
|
mootools-more
|
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-20088
|
2024-11-21 14:45 |
2021-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|