|
195781
|
7.2 |
HIGH
Network
|
linuxfoundation redhat fedoraproject debian
|
ceph ceph_storage fedora debian_linux
|
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who …
|
CWE-287
Improper Authentication
|
CVE-2021-20288
|
2024-11-21 14:46 |
2021-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195782
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_engineering_lifecycle_manager rhapsody_model_manager collaborative_lifecycle_management engineering_test_management engineeri…
|
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20519
|
2024-11-21 14:46 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195783
|
6.5 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vuln…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-20480
|
2024-11-21 14:46 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195784
|
7.8 |
HIGH
Local
|
mongodb
|
compass
|
A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This i…
|
CWE-269
Improper Privilege Management
|
CVE-2021-20334
|
2024-11-21 14:46 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195785
|
9.8 |
CRITICAL
Network
|
htmldoc_project debian
|
htmldoc debian_linux
|
Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.
|
-
|
CVE-2021-20308
|
2024-11-21 14:46 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195786
|
9.8 |
CRITICAL
Network
|
libpano13_project fedoraproject debian
|
libpano13 fedora debian_linux
|
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
|
-
|
CVE-2021-20307
|
2024-11-21 14:46 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195787
|
8.1 |
HIGH
Network
|
nettle_project redhat fedoraproject netapp debian
|
nettle enterprise_linux fedora ontap_select_deploy_administration_utility active_iq_unified_manager debian_linux
|
A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply fun…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20305
|
2024-11-21 14:46 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195788
|
6.5 |
MEDIUM
Network
|
storage_project redhat fedoraproject
|
storage enterprise_linux openshift_container_platform fedora
|
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not…
|
-
|
CVE-2021-20291
|
2024-11-21 14:46 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195789
|
5.3 |
MEDIUM
Network
|
openexr debian
|
openexr debian_linux
|
A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could ca…
|
-
|
CVE-2021-20296
|
2024-11-21 14:46 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195790
|
8.1 |
HIGH
Network
|
zeromq
|
libzmq
|
There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sized changed, but the buffer would remain the same as it is a …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20235
|
2024-11-21 14:46 |
2021-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|