|
196131
|
7.5 |
HIGH
Network
|
python fedoraproject
|
pillow fedora
|
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempt…
|
CWE-20
Improper Input Validation
|
CVE-2021-27923
|
2024-11-21 14:58 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196132
|
7.5 |
HIGH
Network
|
python fedoraproject
|
pillow fedora
|
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attemp…
|
CWE-20
Improper Input Validation
|
CVE-2021-27922
|
2024-11-21 14:58 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196133
|
7.5 |
HIGH
Network
|
python fedoraproject
|
pillow fedora
|
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempte…
|
CWE-20
Improper Input Validation
|
CVE-2021-27921
|
2024-11-21 14:58 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196134
|
8.8 |
HIGH
Network
|
e107
|
e107
|
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
|
CWE-352
Origin Validation Error
|
CVE-2021-27885
|
2024-11-21 14:58 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196135
|
5.5 |
MEDIUM
Local
|
misp
|
misp
|
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.
|
NVD-CWE-noinfo
|
CVE-2021-27904
|
2024-11-21 14:58 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196136
|
6.8 |
MEDIUM
Physics
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint recognition because local high beam mode (LHBM) does not function properly during bright illuminat…
|
NVD-CWE-noinfo
|
CVE-2021-27901
|
2024-11-21 14:58 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196137
|
9.8 |
CRITICAL
Network
|
accellion
|
fta
|
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.
|
CWE-74
Injection
|
CVE-2021-27730
|
2024-11-21 14:58 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196138
|
6.1 |
MEDIUM
Network
|
zend
|
zendto
|
ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27888
|
2024-11-21 14:58 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196139
|
9.8 |
CRITICAL
Network
|
libjxl_project
|
libjxl
|
JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-27804
|
2024-11-21 14:58 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196140
|
6.1 |
MEDIUM
Network
|
accellion
|
fta
|
Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and later.
|
CWE-79
Cross-site Scripting
|
CVE-2021-27731
|
2024-11-21 14:58 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|