|
195741
|
3.3 |
LOW
Local
|
ibm
|
qradar_user_behavior_analytics
|
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-20391
|
2024-11-21 14:46 |
2021-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195742
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-20535
|
2024-11-21 14:46 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195743
|
7.5 |
HIGH
Local
|
qemu debian
|
qemu debian_linux
|
A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating the…
|
CWE-362
Race Condition
|
CVE-2021-20181
|
2024-11-21 14:46 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195744
|
6.0 |
MEDIUM
Local
|
qemu redhat debian
|
qemu enterprise_linux debian_linux
|
An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing …
|
-
|
CVE-2021-20221
|
2024-11-21 14:46 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195745
|
4.3 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform_expansion_pack jboss-ejb-client
|
A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vul…
|
CWE-200
Information Exposure
|
CVE-2021-20250
|
2024-11-21 14:46 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195746
|
4.9 |
MEDIUM
Network
|
mongodb
|
c\#_driver
|
Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain s…
|
CWE-200
Information Exposure
|
CVE-2021-20331
|
2024-11-21 14:46 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195747
|
7.3 |
HIGH
Local
|
redhat
|
keycloak
|
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to t…
|
-
|
CVE-2021-20202
|
2024-11-21 14:46 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195748
|
7.5 |
HIGH
Network
|
samba debian fedoraproject
|
samba debian_linux fedora
|
A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the req…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20277
|
2024-11-21 14:46 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195749
|
7.5 |
HIGH
Network
|
imagemagick debian
|
imagemagick debian_linux
|
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to da…
|
NVD-CWE-Other
|
CVE-2021-20313
|
2024-11-21 14:46 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195750
|
7.5 |
HIGH
Network
|
imagemagick debian
|
imagemagick debian_linux
|
A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by…
|
-
|
CVE-2021-20312
|
2024-11-21 14:46 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|