|
194691
|
9.8 |
CRITICAL
Network
|
ecoscentric
|
ecospro
|
eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary mem…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-27417
|
2024-11-21 14:57 |
2022-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194692
|
6.5 |
MEDIUM
Network
|
silabs
|
micrium_os
|
Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitr…
|
-
|
CVE-2021-27411
|
2024-11-21 14:57 |
2022-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194693
|
7.8 |
HIGH
Local
|
beego
|
beego
|
An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch symlink attacks locally.
|
CWE-59
Link Following
|
CVE-2021-27117
|
2024-11-21 14:57 |
2022-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194694
|
7.8 |
HIGH
Local
|
beego
|
beego
|
An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlink attacks locally.
|
CWE-59
Link Following
|
CVE-2021-27116
|
2024-11-21 14:57 |
2022-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194695
|
5.5 |
MEDIUM
Local
|
kaspersky
|
total_security small_office_security security_cloud endpoint_security anti-virus internet_security
|
A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security. A local user could cause Windows crash by running …
|
NVD-CWE-noinfo
|
CVE-2021-27223
|
2024-11-21 14:57 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194696
|
6.8 |
MEDIUM
Physics
|
ge
|
ur_bootloader_binary
|
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27430
|
2024-11-21 14:57 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194697
|
9.8 |
CRITICAL
Network
|
ge
|
multilin_b30_firmware multilin_b90_firmware multilin_c60_firmware multilin_c70_firmware multilin_c95_firmware multilin_d30_firmware multilin_d60_firmware multilin_f35_firmware
|
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of fi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-27428
|
2024-11-21 14:57 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194698
|
9.8 |
CRITICAL
Network
|
ge
|
multilin_b30_firmware multilin_b90_firmware multilin_c60_firmware multilin_c70_firmware multilin_c95_firmware multilin_d30_firmware multilin_d60_firmware multilin_f35_firmware
|
GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.
|
NVD-CWE-Other
|
CVE-2021-27426
|
2024-11-21 14:57 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194699
|
5.3 |
MEDIUM
Network
|
ge
|
multilin_b30_firmware multilin_b90_firmware multilin_c60_firmware multilin_c70_firmware multilin_c95_firmware multilin_d30_firmware multilin_d60_firmware multilin_f35_firmware
|
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized inf…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-27424
|
2024-11-21 14:57 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194700
|
7.5 |
HIGH
Network
|
ge
|
multilin_b30_firmware multilin_b90_firmware multilin_c60_firmware multilin_c70_firmware multilin_c95_firmware multilin_d30_firmware multilin_d60_firmware multilin_f35_firmware
|
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2021-27422
|
2024-11-21 14:57 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|