|
196131
|
7.5 |
HIGH
Network
|
postscript_project
|
postscript
|
An issue was discovered in the postscript crate before 0.14.0 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via a user-provided Read implement…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2021-26953
|
2024-11-21 14:57 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196132
|
7.5 |
HIGH
Network
|
ms3d_project
|
ms3d
|
An issue was discovered in the ms3d crate before 0.1.3 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via IoReader::read.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2021-26952
|
2024-11-21 14:57 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196133
|
9.8 |
CRITICAL
Network
|
calamine_project
|
calamine
|
An issue was discovered in the calamine crate before 0.17.0 for Rust. It allows attackers to overwrite heap-memory locations because Vec::set_len is used without proper memory claiming, and this unin…
|
CWE-787 CWE-908
Out-of-bounds Write Use of Uninitialized Resource
|
CVE-2021-26951
|
2024-11-21 14:57 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196134
|
9.8 |
CRITICAL
Network
|
gnu debian fedoraproject
|
screen debian_linux fedora
|
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 …
|
CWE-88
Argument Injection
|
CVE-2021-26937
|
2024-11-21 14:57 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196135
|
6.5 |
MEDIUM
Network
|
argoproj
|
argo_cd
|
In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-26921
|
2024-11-21 14:57 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196136
|
5.4 |
MEDIUM
Network
|
roundcube fedoraproject
|
webmail fedora
|
Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26925
|
2024-11-21 14:57 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196137
|
5.5 |
MEDIUM
Local
|
bitmessage
|
pybitmessage
|
PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted apinotifypath value. NOTE: the discoverer states "security mitigation may not …
|
NVD-CWE-noinfo
|
CVE-2021-26917
|
2024-11-21 14:57 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196138
|
9.8 |
CRITICAL
Network
|
probot
|
bot
|
The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins the server" feature (or possibly have unspecified ot…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-26918
|
2024-11-21 14:57 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196139
|
6.1 |
MEDIUM
Network
|
nopcommerce
|
nopcommerce
|
In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discount…
|
CWE-79
Cross-site Scripting
|
CVE-2021-26916
|
2024-11-21 14:57 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196140
|
8.1 |
HIGH
Network
|
netmotionsoftware
|
netmotion_mobility
|
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-26915
|
2024-11-21 14:57 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|