|
196711
|
5.5 |
MEDIUM
Local
|
sox_project
|
sox
|
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an applicati…
|
-
|
CVE-2021-23172
|
2024-11-21 14:51 |
2022-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196712
|
5.5 |
MEDIUM
Local
|
sox_project
|
sox
|
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an appli…
|
-
|
CVE-2021-23159
|
2024-11-21 14:51 |
2022-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196713
|
7.8 |
HIGH
Local
|
libarchive fedoraproject redhat debian
|
libarchive fedora enterprise_linux enterprise_linux_for_power_little_endian enterprise_linux_for_ibm_z_systems enterprise_linux_server_for_power_little_endian_update_services_for_sap_s…
|
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user…
|
-
|
CVE-2021-23177
|
2024-11-21 14:51 |
2022-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196714
|
7.8 |
HIGH
Local
|
intel
|
killer_wi-fi_6e_ax1690_firmware killer_wi-fi_6e_ax1675_firmware proset_wi-fi_6e_ax210_firmware wi-fi_6e_ax211_firmware wi-fi_6e_ax411_firmware
|
Improper initialization for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-665
Improper Initialization
|
CVE-2021-23223
|
2024-11-21 14:51 |
2022-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196715
|
3.3 |
LOW
Local
|
intel
|
wireless-ac_9560_firmware dual_band_wireless-ac_3165_firmware dual_band_wireless-ac_3168_firmware wireless-ac_9462_firmware wireless-ac_9461_firmware killer_ac_1550_firmware killer_…
|
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an authenticated user to potentially enable information disclosure via local access.
|
NVD-CWE-Other
|
CVE-2021-23188
|
2024-11-21 14:51 |
2022-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196716
|
7.1 |
HIGH
Local
|
intel
|
wi-fi_6_ax411_firmware wi-fi_6_ax211_firmware wi-fi_6_ax210_firmware wi-fi_6_ax201_firmware wi-fi_6_ax200_firmware wireless-ac_9560_firmware wireless-ac_9462_firmware wireless-ac…
|
Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow a privileged user to potentially enable information disclos…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-23179
|
2024-11-21 14:51 |
2022-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196717
|
6.5 |
MEDIUM
Adjacent
|
intel
|
wireless-ac_9560_firmware dual_band_wireless-ac_3165_firmware dual_band_wireless-ac_3168_firmware wireless-ac_9462_firmware wireless-ac_9461_firmware killer_ac_1550_firmware killer_…
|
Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.
|
CWE-125
Out-of-bounds Read
|
CVE-2021-23168
|
2024-11-21 14:51 |
2022-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196718
|
6.1 |
MEDIUM
Network
|
flask-security_project
|
flask-security
|
This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an a…
|
CWE-601
Open Redirect
|
CVE-2021-23385
|
2024-11-21 14:51 |
2022-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196719
|
9.8 |
CRITICAL
Network
|
otp-generator_project
|
otp-generator
|
The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-23451
|
2024-11-21 14:51 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196720
|
9.8 |
CRITICAL
Network
|
merge_project
|
merge
|
All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2021-23397
|
2024-11-21 14:51 |
2022-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|