|
196711
|
8.8 |
HIGH
Local
|
qualcomm
|
aqt1000_firmware ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware fsm10055_firmware fsm10056_firmware mdm9150_firmware qca6390_firmware qca6391_firmware<…
|
Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industria…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-1942
|
2024-11-21 14:45 |
2022-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196712
|
9.8 |
CRITICAL
Network
|
skolelinux debian
|
debian-edu-config debian_linux
|
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which co…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-20001
|
2024-11-21 14:45 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196713
|
8.8 |
HIGH
Network
|
sonicwall
|
sonicos
|
A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the fi…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20048
|
2024-11-21 14:45 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196714
|
8.8 |
HIGH
Network
|
sonicwall
|
sonicos
|
A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in t…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-20046
|
2024-11-21 14:45 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196715
|
6.5 |
MEDIUM
Local
|
qualcomm
|
qca6391_firmware qcm6490_firmware qcs6490_firmware qrb5165_firmware qrb5165n_firmware sd690_5g_firmware sd750g_firmware sd765_firmware sd765g_firmware sd768g_firmware sd…
|
Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-1918
|
2024-11-21 14:45 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196716
|
7.8 |
HIGH
Local
|
qualcomm
|
ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware csrb31024_firmware fsm10055_firmware fsm10056_firmware mdm9150_firmware mdm9205_firmware mdm9628_firmwar…
|
Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-1894
|
2024-11-21 14:45 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196717
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-2640-us_firmware
|
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-20132
|
2024-11-21 14:45 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196718
|
8.4 |
HIGH
Adjacent
|
dlink
|
dir-2640-us_firmware
|
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set an arbitrary file…
|
CWE-22
Path Traversal
|
CVE-2021-20134
|
2024-11-21 14:45 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196719
|
6.1 |
MEDIUM
Adjacent
|
dlink
|
dir-2640-us_firmware
|
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set the "message of t…
|
CWE-22
Path Traversal
|
CVE-2021-20133
|
2024-11-21 14:45 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196720
|
7.5 |
HIGH
Network
|
sonicwall
|
sma_100_firmware sma_200_firmware sma_210_firmware sma_400_firmware sma_410_firmware sma_500v_firmware
|
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
|
NVD-CWE-Other
|
CVE-2021-20050
|
2024-11-21 14:45 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|