|
195461
|
7.5 |
HIGH
Network
|
samsung
|
tizenrt
|
Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected …
|
-
|
CVE-2021-22684
|
2024-11-21 14:50 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195462
|
7.5 |
HIGH
Network
|
huawei
|
elf-g10hn
|
There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to exploit this vulnerability. Due to insufficient security design, successful exp…
|
NVD-CWE-noinfo
|
CVE-2021-22449
|
2024-11-21 14:50 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195463
|
7.5 |
HIGH
Network
|
nodejs oracle netapp siemens debian
|
node.js peoplesoft_enterprise_peopletools graalvm jd_edwards_enterpriseone_tools nextgen_api sinec_infrastructure_network_services debian_linux
|
Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
|
CWE-416
Use After Free
|
CVE-2021-22940
|
2024-11-21 14:50 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195464
|
5.3 |
MEDIUM
Network
|
nodejs oracle netapp siemens debian
|
node.js peoplesoft_enterprise_peopletools graalvm mysql_cluster jd_edwards_enterpriseone_tools nextgen_api sinec_infrastructure_network_services debian_linux
|
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would …
|
CWE-295
Improper Certificate Validation
|
CVE-2021-22939
|
2024-11-21 14:50 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195465
|
7.2 |
HIGH
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure
|
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.
|
CWE-77
Command Injection
|
CVE-2021-22938
|
2024-11-21 14:50 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195466
|
7.2 |
HIGH
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure
|
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-22937
|
2024-11-21 14:50 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195467
|
6.1 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure
|
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-22936
|
2024-11-21 14:50 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195468
|
7.2 |
HIGH
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure
|
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.
|
CWE-77
Command Injection
|
CVE-2021-22935
|
2024-11-21 14:50 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195469
|
7.2 |
HIGH
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure
|
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buffer overfl…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-22934
|
2024-11-21 14:50 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195470
|
6.5 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure
|
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.
|
CWE-22
Path Traversal
|
CVE-2021-22933
|
2024-11-21 14:50 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|