|
194751
|
9.8 |
CRITICAL
Network
|
wowonder
|
wowonder
|
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-27200
|
2024-11-21 14:57 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194752
|
9.8 |
CRITICAL
Network
|
hillrom
|
spot_vital_signs_4400 connex_central_station connex_device_integration_suite_network_connectivity_engine connex_integrated_wall_system connex_spot_monitor connex_vital_signs_monitor
|
The affected product is vulnerable to an out-of-bounds write, which may result in corruption of data or code execution on the Welch Allyn medical device management tools (Welch Allyn Service Tool: ve…
|
-
|
CVE-2021-27410
|
2024-11-21 14:57 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194753
|
7.5 |
HIGH
Network
|
hillrom
|
spot_vital_signs_4400 connex_central_station connex_device_integration_suite_network_connectivity_engine connex_integrated_wall_system connex_spot_monitor connex_vital_signs_monitor
|
The affected product is vulnerable to an out-of-bounds read, which can cause information leakage leading to arbitrary code execution if chained to the out-of-bounds write vulnerability on the Welch A…
|
-
|
CVE-2021-27408
|
2024-11-21 14:57 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194754
|
7.5 |
HIGH
Network
|
netapp
|
e-series_santricity_os_controller
|
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configu…
|
NVD-CWE-noinfo
|
CVE-2021-26996
|
2024-11-21 14:57 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194755
|
8.8 |
HIGH
Network
|
netapp
|
e-series_santricity_os_controller
|
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow privileged attackers to execute arbitrary co…
|
NVD-CWE-noinfo
|
CVE-2021-26995
|
2024-11-21 14:57 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194756
|
5.3 |
MEDIUM
Network
|
netapp
|
e-series_santricity_os_controller
|
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to cause a partial Denial …
|
NVD-CWE-noinfo
|
CVE-2021-26993
|
2024-11-21 14:57 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194757
|
6.5 |
MEDIUM
Network
|
netapp
|
e-series_santricity_os_controller
|
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information vi…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-26997
|
2024-11-21 14:57 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194758
|
5.5 |
MEDIUM
Local
|
long_range_zip_project debian
|
long_range_zip debian_linux
|
Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.
|
CWE-416
Use After Free
|
CVE-2021-27347
|
2024-11-21 14:57 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194759
|
5.5 |
MEDIUM
Local
|
long_range_zip_project debian
|
long_range_zip debian_linux
|
A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-27345
|
2024-11-21 14:57 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194760
|
7.8 |
HIGH
Local
|
siemens
|
teamcenter_visualization jt2go
|
A vulnerability has been identified in JT2Go (All versions < V13.1.0.3), Teamcenter Visualization (All versions < V13.1.0.3). The TIFF_loader.dll library in affected applications lacks proper validat…
|
-
|
CVE-2021-27390
|
2024-11-21 14:57 |
2021-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|