|
198231
|
9.8 |
CRITICAL
Network
|
libspf2 redhat fedoraproject
|
libspf2 enterprise_linux fedora
|
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20314
|
2024-11-21 14:46 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198232
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-20427
|
2024-11-21 14:46 |
2021-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198233
|
4.3 |
MEDIUM
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281.
|
NVD-CWE-Other
|
CVE-2021-20420
|
2024-11-21 14:46 |
2021-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198234
|
9.8 |
CRITICAL
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
|
CWE-521
Weak Password Requirements
|
CVE-2021-20418
|
2024-11-21 14:46 |
2021-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198235
|
5.3 |
MEDIUM
Local
|
ibm
|
tivoli_workload_scheduler
|
IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges.…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20349
|
2024-11-21 14:46 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198236
|
5.3 |
MEDIUM
Network
|
mitsubishielectric
|
r08sfcpu_firmware r16sfcpu_firmware r32sfcpu_firmware r120sfcpu_firmware r08psfcpu_firmware r16psfcpu_firmware r32psfcpu_firmware r120psfcpu_firmware
|
Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16/32/120SFCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote un…
|
CWE-287
Improper Authentication
|
CVE-2021-20598
|
2024-11-21 14:46 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198237
|
9.1 |
CRITICAL
Network
|
mitsubishielectric
|
r08sfcpu_firmware r16sfcpu_firmware r32sfcpu_firmware r120sfcpu_firmware r08psfcpu_firmware r16psfcpu_firmware r32psfcpu_firmware r120psfcpu_firmware
|
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-20597
|
2024-11-21 14:46 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198238
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
r08sfcpu_firmware r16sfcpu_firmware r32sfcpu_firmware r120sfcpu_firmware r08psfcpu_firmware r16psfcpu_firmware r32psfcpu_firmware r120psfcpu_firmware
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubish…
|
CWE-200
Information Exposure
|
CVE-2021-20594
|
2024-11-21 14:46 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198239
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
gt_softgot2000 got2000_gt27_firmware got2000_gt25_firmware got2000_gt23_firmware
|
Missing synchronization vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.39.010, GT25 model communication driver versions 01.19.000 through 01.39.010 and …
|
CWE-662
Improper Synchronization
|
CVE-2021-20592
|
2024-11-21 14:46 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198240
|
5.3 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive information to an unauthorized user through HTTP GET requests. This information cou…
|
NVD-CWE-noinfo
|
CVE-2021-20541
|
2024-11-21 14:46 |
2021-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|