|
196181
|
7.8 |
HIGH
Local
|
amd
|
enterprise_driver radeon_pro_software radeon_software radeon_rx_vega_56_firmware radeon_rx_vega_64_firmware ryzen_3_5300ge_firmware ryzen_3_5300g_firmware ryzen_5_5600ge_firmware…
|
Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel.
|
NVD-CWE-noinfo
|
CVE-2021-26391
|
2024-11-21 14:56 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196182
|
7.5 |
HIGH
Network
|
lannerinc
|
iac-ast2500a_firmware
|
A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot commands to the BMC, causing a Denial-of-Service (DoS) c…
|
NVD-CWE-Other
|
CVE-2021-26733
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196183
|
5.3 |
MEDIUM
Network
|
lannerinc
|
iac-ast2500a_firmware
|
A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network configuration of the BMC. This issue affects: Lanner I…
|
NVD-CWE-Other
|
CVE-2021-26732
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196184
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticated attacker to execute arbitrary code with the same…
|
CWE-77 CWE-787
Command Injection Out-of-bounds Write
|
CVE-2021-26731
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196185
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allows an attacker to execute arbitrary code with the same privileges as the server …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-26730
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196186
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges …
|
CWE-77 CWE-787
Command Injection Out-of-bounds Write
|
CVE-2021-26729
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196187
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server…
|
CWE-77 CWE-787
Command Injection Out-of-bounds Write
|
CVE-2021-26728
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196188
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privilege…
|
CWE-77 CWE-787
Command Injection Out-of-bounds Write
|
CVE-2021-26727
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196189
|
7.5 |
HIGH
Network
|
wisa
|
smart_wing_cms
|
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server witho…
|
CWE-20 CWE-494
Improper Input Validation Download of Code Without Integrity Check
|
CVE-2021-26639
|
2024-11-21 14:56 |
2022-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196190
|
7.8 |
HIGH
Local
|
amd
|
ryzen_7_5700g_firmware ryzen_7_5700ge_firmware ryzen_5_5600g_firmware ryzen_5_5600ge_firmware ryzen_3_5300g_firmware ryzen_3_5300ge_firmware ryzen_9_5980hx_firmware ryzen_9_5980h…
|
A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2021-26384
|
2024-11-21 14:56 |
2022-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|