|
197851
|
5.5 |
MEDIUM
Local
|
trendmicro
|
serverprotect
|
A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The speci…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-25225
|
2024-11-21 14:54 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197852
|
5.5 |
MEDIUM
Local
|
trendmicro
|
serverprotect
|
A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a denial-of-service on the affected product. The speci…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-25224
|
2024-11-21 14:54 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197853
|
8.8 |
HIGH
Network
|
wisc
|
htcondor
|
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-25312
|
2024-11-21 14:54 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197854
|
9.9 |
CRITICAL
Network
|
wisc
|
htcondor
|
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by ro…
|
CWE-22
Path Traversal
|
CVE-2021-25311
|
2024-11-21 14:54 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197855
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25325
|
2024-11-21 14:54 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197856
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25324
|
2024-11-21 14:54 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197857
|
9.1 |
CRITICAL
Network
|
misp
|
misp
|
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2021-25323
|
2024-11-21 14:54 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197858
|
7.8 |
HIGH
Local
|
opendesign siemens
|
drawings_software_development_kit jt2go teamcenter_visualization comos
|
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A stack-based buffer overflow vulnerability exists when the recover operation is run with malformed .DXF and .DWG files. T…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25178
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197859
|
7.8 |
HIGH
Local
|
opendesign siemens
|
drawings_software_development_kit jt2go teamcenter_visualization comos
|
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Confusion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, pot…
|
CWE-843
Type Confusion
|
CVE-2021-25177
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197860
|
7.8 |
HIGH
Local
|
opendesign siemens
|
drawings_software_development_kit jt2go teamcenter_visualization comos
|
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer dereference exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash,…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-25176
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|