|
194751
|
5.5 |
MEDIUM
Local
|
asus
|
gputweak_ii
|
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enable low-privileged users to achieve Denial of Servi…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-28686
|
2024-11-21 15:00 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194752
|
7.8 |
HIGH
Local
|
asus
|
gputweak_ii
|
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines that map physical memo…
|
NVD-CWE-Other
|
CVE-2021-28685
|
2024-11-21 15:00 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194753
|
7.8 |
HIGH
Local
|
libretro
|
retroarch
|
The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers …
|
CWE-78
OS Command
|
CVE-2021-28927
|
2024-11-21 15:00 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194754
|
6.5 |
MEDIUM
Local
|
linux debian
|
linux_kernel debian_linux
|
The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions…
|
CWE-665
Improper Initialization
|
CVE-2021-28688
|
2024-11-21 15:00 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194755
|
5.5 |
MEDIUM
Local
|
linuxfoundation sylabs
|
umoci singularity
|
Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.
|
CWE-20
Improper Input Validation
|
CVE-2021-29136
|
2024-11-21 15:00 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194756
|
5.3 |
MEDIUM
Network
|
djangoproject debian fedoraproject
|
django debian_linux fedora
|
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were no…
|
CWE-22
Path Traversal
|
CVE-2021-28658
|
2024-11-21 15:00 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194757
|
7.8 |
HIGH
Local
|
serenityos
|
serenityos
|
SerenityOS fixed as of c9f25bca048443e317f1994ba9b106f2386688c3 contains a buffer overflow vulnerability in LibTextCode through opening a crafted file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-28874
|
2024-11-21 15:00 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194758
|
7.8 |
HIGH
Local
|
svelte
|
svelte
|
The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.
|
NVD-CWE-noinfo
|
CVE-2021-29261
|
2024-11-21 15:00 |
2021-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194759
|
7.8 |
HIGH
Local
|
vim_project
|
vim
|
VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration.
|
NVD-CWE-noinfo
|
CVE-2021-28832
|
2024-11-21 15:00 |
2021-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194760
|
5.3 |
MEDIUM
Network
|
magpierss_project
|
magpierss
|
Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_debug.php or /scripts/magpie_simple.php page, it's po…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-28941
|
2024-11-21 15:00 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|