|
195981
|
5.3 |
MEDIUM
Network
|
redwood
|
report2web
|
A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/default.htm turl parame…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2021-26711
|
2024-11-21 14:56 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195982
|
6.1 |
MEDIUM
Network
|
redwood
|
report2web
|
A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-26710
|
2024-11-21 14:56 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195983
|
7.0 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup fas_baseboard_management_controller aff_baseboard_management_controller solidfire_\&_hci_management_node solidfire_baseboard_management_controller base…
|
A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The ra…
|
CWE-667
Improper Locking
|
CVE-2021-26708
|
2024-11-21 14:56 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195984
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021).
|
CWE-416
Use After Free
|
CVE-2021-26689
|
2024-11-21 14:56 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195985
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021).
|
NVD-CWE-noinfo
|
CVE-2021-26688
|
2024-11-21 14:56 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195986
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, the HostnameVerified default is mishandled. The LG ID is LVE-SMP-200029 (Februa…
|
NVD-CWE-noinfo
|
CVE-2021-26687
|
2024-11-21 14:56 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195987
|
7.5 |
HIGH
Network
|
marc_project
|
marc
|
An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated memory, violating soundness.
|
NVD-CWE-noinfo
|
CVE-2021-26308
|
2024-11-21 14:56 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195988
|
5.5 |
MEDIUM
Local
|
raw-cpuid_project
|
raw-cpuid
|
An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It allows __cpuid_count() calls even if the processor does not support the CPUID instruction, which is unsound and causes a deter…
|
NVD-CWE-Other
|
CVE-2021-26307
|
2024-11-21 14:56 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195989
|
7.5 |
HIGH
Network
|
raw-cpuid_project
|
raw-cpuid
|
An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() methods.
|
NVD-CWE-Other
|
CVE-2021-26306
|
2024-11-21 14:56 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195990
|
9.8 |
CRITICAL
Network
|
cdr_project
|
cdr
|
An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, viola…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2021-26305
|
2024-11-21 14:56 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|