|
196611
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
Windows Event Tracing Information Disclosure Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-24107
|
2024-11-21 14:52 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196612
|
4.6 |
MEDIUM
Local
|
microsoft
|
sharepoint_foundation sharepoint_enterprise_server sharepoint_server
|
Microsoft SharePoint Server Spoofing Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-24104
|
2024-11-21 14:52 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196613
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2019 windows_server_2016
|
DirectX Elevation of Privilege Vulnerability
|
CWE-269
Improper Privilege Management
|
CVE-2021-24095
|
2024-11-21 14:52 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196614
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2016 windows_10
|
Windows Error Reporting Elevation of Privilege Vulnerability
|
CWE-269
Improper Privilege Management
|
CVE-2021-24090
|
2024-11-21 14:52 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196615
|
7.8 |
HIGH
Local
|
microsoft
|
high_efficiency_video_coding
|
HEVC Video Extensions Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-24089
|
2024-11-21 14:52 |
2021-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196616
|
9.8 |
CRITICAL
Network
|
facebook
|
gameroom
|
The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affect…
|
CWE-88
Argument Injection
|
CVE-2021-24030
|
2024-11-21 14:52 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196617
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm
|
Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading to a heap overflow. This issue affects HH…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-24025
|
2024-11-21 14:52 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196618
|
5.6 |
MEDIUM
Network
|
facebook
|
react-dev-utils
|
react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed. This function is typically used from react-script…
|
CWE-78
OS Command
|
CVE-2021-24033
|
2024-11-21 14:52 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196619
|
4.7 |
MEDIUM
Local
|
facebook
|
zstandard
|
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-24032
|
2024-11-21 14:52 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196620
|
5.5 |
MEDIUM
Local
|
facebook
|
zstandard
|
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output f…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-24031
|
2024-11-21 14:52 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|