|
195391
|
7.8 |
HIGH
Local
|
sonicwall
|
global_vpn_client
|
SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code ex…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-20047
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195392
|
9.8 |
CRITICAL
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_410_firmware sma_400_firmware sma_500v_firmware
|
A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-20045
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195393
|
8.8 |
HIGH
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_410_firmware sma_400_firmware sma_500v_firmware
|
A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA…
|
CWE-78
OS Command
|
CVE-2021-20044
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195394
|
8.8 |
HIGH
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_410_firmware sma_400_firmware sma_500v_firmware
|
A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. This vulnera…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20043
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195395
|
9.8 |
CRITICAL
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_410_firmware sma_400_firmware sma_500v_firmware
|
An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appl…
|
NVD-CWE-Other
|
CVE-2021-20042
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195396
|
7.5 |
HIGH
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_410_firmware sma_400_firmware sma_500v_firmware
|
An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit cond…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2021-20041
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195397
|
7.5 |
HIGH
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_410_firmware sma_400_firmware sma_500v_firmware
|
A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA …
|
CWE-22
Path Traversal
|
CVE-2021-20040
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195398
|
8.8 |
HIGH
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_410_firmware sma_400_firmware sma_500v_firmware
|
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' u…
|
CWE-78
OS Command
|
CVE-2021-20039
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195399
|
9.8 |
CRITICAL
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_410_firmware sma_400_firmware sma_500v_firmware
|
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' use…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20038
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195400
|
7.5 |
HIGH
Network
|
qualcomm
|
ar8035_firmware qca6390_firmware qca6391_firmware qca6421_firmware qca6426_firmware qca6431_firmware qca6436_firmware qca6574a_firmware qca6574au_firmware qca6595au_firmwar…
|
Possible denial of service scenario due to improper input validation of received NAS OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon I…
|
CWE-617
Reachable Assertion
|
CVE-2021-1982
|
2024-11-21 14:45 |
2021-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|