|
196411
|
7.1 |
HIGH
Local
|
linux debian netapp oracle canonical
|
linux_kernel debian_linux solidfire_baseboard_management_controller_firmware tekelec_platform_distribution ubuntu_linux
|
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
|
CWE-125
Out-of-bounds Read
|
CVE-2021-27364
|
2024-11-21 14:57 |
2021-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196412
|
4.4 |
MEDIUM
Local
|
linux debian netapp
|
linux_kernel debian_linux cloud_backup solidfire_baseboard_management_controller_firmware
|
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the…
|
NVD-CWE-noinfo
|
CVE-2021-27363
|
2024-11-21 14:57 |
2021-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196413
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
br200_firmware br500_firmware d7800_firmware ex6100v2_firmware ex6150v2_firmware ex6250_firmware ex6400_firmware ex6400v2_firmware ex6410_firmware ex6420_firmware ex7300…
|
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not …
|
-
|
CVE-2021-27257
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196414
|
8.8 |
HIGH
Adjacent
|
netgear
|
br200_firmware br500_firmware d7800_firmware ex6100v2_firmware ex6150v2_firmware ex6250_firmware ex6400_firmware ex6400v2_firmware ex6410_firmware ex6420_firmware ex7300…
|
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Although authentication is required to exploit thi…
|
-
|
CVE-2021-27256
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196415
|
8.8 |
HIGH
Adjacent
|
netgear
|
br200_firmware br500_firmware d7800_firmware ex6100v2_firmware ex6150v2_firmware ex6250_firmware ex6400_firmware ex6400v2_firmware ex6410_firmware ex6420_firmware ex7300…
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability…
|
-
|
CVE-2021-27255
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196416
|
8.8 |
HIGH
Adjacent
|
netgear
|
br200_firmware br500_firmware d7800_firmware ex6100v2_firmware ex6150v2_firmware ex6250_firmware ex6400_firmware ex6400v2_firmware ex6410_firmware ex6420_firmware ex7300…
|
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific fl…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27254
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196417
|
6.3 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management …
|
CWE-78
OS Command
|
CVE-2021-26970
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196418
|
6.8 |
MEDIUM
Network
|
cncf
|
spire
|
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issu…
|
CWE-863
Incorrect Authorization
|
CVE-2021-27099
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196419
|
8.1 |
HIGH
Network
|
cncf
|
spire
|
In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible iss…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-27098
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196420
|
6.3 |
MEDIUM
Network
|
arubanetworks
|
airwave
|
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management …
|
NVD-CWE-noinfo
|
CVE-2021-26971
|
2024-11-21 14:57 |
2021-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|