|
195341
|
8.8 |
HIGH
Network
|
ribbonsoft fedoraproject debian
|
dxflib extra_packages_for_enterprise_linux fedora debian_linux
|
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can …
|
-
|
CVE-2021-21897
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195342
|
6.4 |
MEDIUM
Local
|
saltstack fedoraproject
|
salt fedora
|
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This …
|
CWE-362
Race Condition
|
CVE-2021-22004
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195343
|
7.5 |
HIGH
Network
|
saltstack fedoraproject debian
|
salt fedora debian_linux
|
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
|
NVD-CWE-noinfo
|
CVE-2021-21996
|
2024-11-21 14:49 |
2021-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195344
|
7.5 |
HIGH
Network
|
vmware
|
identity_manager workspace_one_access cloud_foundation vrealize_suite_lifecycle_manager
|
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute forc…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-22003
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195345
|
9.8 |
CRITICAL
Network
|
vmware
|
identity_manager workspace_one_access cloud_foundation vrealize_suite_lifecycle_manager
|
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network…
|
CWE-287
Improper Authentication
|
CVE-2021-22002
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195346
|
7.5 |
HIGH
Network
|
vmware
|
workspace_one_uem_console
|
VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate lim…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-22029
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195347
|
9.8 |
CRITICAL
Network
|
att
|
xmill
|
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2021-21811
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195348
|
5.4 |
MEDIUM
Network
|
vmware
|
vrealize_log_insight cloud_foundation
|
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a mali…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22021
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195349
|
7.5 |
HIGH
Network
|
vmware
|
vrealize_suite_lifecycle_manager cloud_foundation vrealize_operations_manager
|
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manage…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22027
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195350
|
7.5 |
HIGH
Network
|
vmware
|
vrealize_suite_lifecycle_manager cloud_foundation vrealize_operations_manager
|
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manage…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22026
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|