|
197701
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8017_firmware apq8037_firmware apq8053_firmware apq8064au_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmwar…
|
Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-1890
|
2024-11-21 14:45 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197702
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8017_firmware apq8037_firmware apq8053_firmware apq8064au_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmwar…
|
Possible buffer overflow due to lack of length check in Trusted Application in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdr…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-1889
|
2024-11-21 14:45 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197703
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8017_firmware apq8037_firmware apq8053_firmware apq8064au_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmwar…
|
Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdrago…
|
CWE-415
Double Free
|
CVE-2021-1888
|
2024-11-21 14:45 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197704
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8017_firmware apq8037_firmware apq8053_firmware apq8064au_firmware apq8096au_firmware aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmwar…
|
Incorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snap…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-1886
|
2024-11-21 14:45 |
2021-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197705
|
8.1 |
HIGH
Adjacent
|
sonicwall
|
switch
|
Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a system instability or potentially read sensitive information from the memory loc…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-20024
|
2024-11-21 14:45 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197706
|
5.4 |
MEDIUM
Adjacent
|
sloan
|
optima_eaf-100_firmware optima_eaf-150_firmware optima_eaf-200_firmware optima_eaf-225_firmware optima_eaf-250_firmware optima_eaf-275_firmware optima_eaf-350_firmware optima_eaf…
|
There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kin…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-20107
|
2024-11-21 14:45 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197707
|
6.7 |
MEDIUM
Local
|
tenable
|
nessus
|
Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaini…
|
NVD-CWE-noinfo
|
CVE-2021-20079
|
2024-11-21 14:45 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197708
|
6.1 |
MEDIUM
Network
|
machform
|
machform
|
Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.
|
CWE-601
Open Redirect
|
CVE-2021-20105
|
2024-11-21 14:45 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197709
|
8.1 |
HIGH
Network
|
machform
|
machform
|
Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20104
|
2024-11-21 14:45 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197710
|
6.1 |
MEDIUM
Network
|
machform
|
machform
|
Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded with forms through upload.php.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20103
|
2024-11-21 14:45 |
2021-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|