|
194931
|
6.5 |
MEDIUM
Network
|
vmware
|
spring_advanced_message_queuing_protocol
|
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. Thi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-22095
|
2024-11-21 14:49 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194932
|
9.8 |
CRITICAL
Network
|
vmware
|
vcenter_server
|
The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22049
|
2024-11-21 14:49 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194933
|
7.5 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain acce…
|
NVD-CWE-noinfo
|
CVE-2021-21980
|
2024-11-21 14:49 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194934
|
5.9 |
MEDIUM
Network
|
huawei
|
ips_module_firmware ngfw_module_firmware secospace_usg6300_firmware secospace_usg6500_firmware secospace_usg6600_firmware usg9500_firmware
|
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages betwee…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-22356
|
2024-11-21 14:49 |
2021-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194935
|
8.8 |
HIGH
Network
|
librecad debian fedoraproject
|
libdxfrw debian_linux fedora
|
A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write.…
|
-
|
CVE-2021-21898
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194936
|
8.8 |
HIGH
Network
|
librecad debian fedoraproject
|
libdxfrw debian_linux fedora
|
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability.…
|
-
|
CVE-2021-21900
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194937
|
8.8 |
HIGH
Network
|
librecad fedoraproject debian
|
libdxfrw fedora debian_linux
|
A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow…
|
-
|
CVE-2021-21899
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194938
|
6.5 |
MEDIUM
Network
|
greenplum
|
greenplum
|
In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-22030
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194939
|
9.1 |
CRITICAL
Network
|
greenplum
|
greenplum
|
In versions of Greenplum database prior to 5.28.6 and 6.14.0, greenplum database contains a file path traversal vulnerability leading to information disclosure from the file system. A malicious user …
|
CWE-22
Path Traversal
|
CVE-2021-22028
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194940
|
8.8 |
HIGH
Network
|
vmware
|
spring_cloud_netflix
|
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view t…
|
CWE-94
Code Injection
|
CVE-2021-22053
|
2024-11-21 14:49 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|