|
196611
|
9.8 |
CRITICAL
Network
|
onlyoffice
|
document_server
|
A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remo…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25832
|
2024-11-21 14:55 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196612
|
9.8 |
CRITICAL
Network
|
onlyoffice
|
document_server
|
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into PPTX format. Using …
|
NVD-CWE-noinfo
|
CVE-2021-25831
|
2024-11-21 14:55 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196613
|
9.8 |
CRITICAL
Network
|
onlyoffice
|
document_server
|
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. U…
|
NVD-CWE-noinfo
|
CVE-2021-25830
|
2024-11-21 14:55 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196614
|
7.5 |
HIGH
Network
|
onlyoffice
|
document_server
|
An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack th…
|
NVD-CWE-noinfo
|
CVE-2021-25829
|
2024-11-21 14:55 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196615
|
7.8 |
HIGH
Local
|
collaboraoffice
|
online
|
"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and ref…
|
CWE-269
Improper Privilege Management
|
CVE-2021-25630
|
2024-11-21 14:55 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196616
|
8.8 |
HIGH
Network
|
atlassian
|
jira_server_for_slack
|
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.
|
CWE-74
Injection
|
CVE-2021-26068
|
2024-11-21 14:55 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196617
|
9.8 |
CRITICAL
Network
|
smarty debian
|
smarty debian_linux
|
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
|
CWE-94
Code Injection
|
CVE-2021-26120
|
2024-11-21 14:55 |
2021-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196618
|
7.5 |
HIGH
Network
|
smarty debian
|
smarty debian_linux
|
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
|
NVD-CWE-noinfo
|
CVE-2021-26119
|
2024-11-21 14:55 |
2021-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196619
|
7.2 |
HIGH
Network
|
baby_care_system_project
|
baby_care_system
|
An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-25780
|
2024-11-21 14:55 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196620
|
9.8 |
CRITICAL
Network
|
baby_care_system_project
|
baby_care_system
|
Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page.
|
CWE-89
SQL Injection
|
CVE-2021-25779
|
2024-11-21 14:55 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|