|
197321
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25324
|
2024-11-21 14:54 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197322
|
9.1 |
CRITICAL
Network
|
misp
|
misp
|
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2021-25323
|
2024-11-21 14:54 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197323
|
7.8 |
HIGH
Local
|
opendesign siemens
|
drawings_software_development_kit jt2go teamcenter_visualization comos
|
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A stack-based buffer overflow vulnerability exists when the recover operation is run with malformed .DXF and .DWG files. T…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25178
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197324
|
7.8 |
HIGH
Local
|
opendesign siemens
|
drawings_software_development_kit jt2go teamcenter_visualization comos
|
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Confusion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, pot…
|
CWE-843
Type Confusion
|
CVE-2021-25177
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197325
|
7.8 |
HIGH
Local
|
opendesign siemens
|
drawings_software_development_kit jt2go teamcenter_visualization comos
|
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer dereference exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash,…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-25176
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197326
|
7.8 |
HIGH
Local
|
opendesign siemens
|
drawings_software_development_kit jt2go teamcenter_visualization comos
|
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Conversion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, po…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2021-25175
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197327
|
7.8 |
HIGH
Local
|
opendesign siemens
|
drawings_software_development_kit jt2go teamcenter_visualization comos
|
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potent…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25174
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197328
|
7.8 |
HIGH
Local
|
opendesign siemens
|
drawings_software_development_kit jt2go teamcenter_visualization comos
|
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to c…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-25173
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197329
|
6.1 |
MEDIUM
Network
|
opencats
|
opencats
|
OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25295
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197330
|
9.8 |
CRITICAL
Network
|
opencats
|
opencats
|
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php calls unserialize for the parametersactivity:Activ…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-25294
|
2024-11-21 14:54 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|