|
197811
|
7.5 |
HIGH
Network
|
contiki-os
|
contiki
|
An issue was discovered in Contiki through 3.0. When sending an ICMPv6 error message because of invalid extension header options in an incoming IPv6 packet, there is an attempt to remove the RPL exte…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2021-28362
|
2024-11-21 14:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197812
|
5.5 |
MEDIUM
Local
|
netflix
|
priam
|
Priam uses File.createTempFile, which gives the permissions on that file -rw-r--r--. An attacker with read access to the local filesystem can read anything written there by the Priam process.
|
NVD-CWE-noinfo
|
CVE-2021-28100
|
2024-11-21 14:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197813
|
4.4 |
MEDIUM
Local
|
netflix
|
hollow
|
In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure sourc…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-28099
|
2024-11-21 14:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197814
|
7.5 |
HIGH
Network
|
grafana
|
grafana
|
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticate…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-28148
|
2024-11-21 14:59 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197815
|
6.5 |
MEDIUM
Network
|
grafana
|
grafana
|
The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication s…
|
NVD-CWE-Other
|
CVE-2021-28147
|
2024-11-21 14:59 |
2021-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197816
|
6.5 |
MEDIUM
Network
|
grafana
|
grafana
|
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any aut…
|
CWE-863
Incorrect Authorization
|
CVE-2021-28146
|
2024-11-21 14:59 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197817
|
7.5 |
HIGH
Network
|
kde
|
discover
|
libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of…
|
NVD-CWE-noinfo
|
CVE-2021-28117
|
2024-11-21 14:59 |
2021-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197818
|
5.3 |
MEDIUM
Network
|
torproject fedoraproject
|
tor fedora
|
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
|
CWE-617
Reachable Assertion
|
CVE-2021-28090
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197819
|
7.5 |
HIGH
Network
|
torproject fedoraproject
|
tor fedora
|
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-28089
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197820
|
6.1 |
MEDIUM
Network
|
compassplus
|
tranzware_e-commerce_payment_gateway
|
index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability
|
CWE-79
Cross-site Scripting
|
CVE-2021-28126
|
2024-11-21 14:59 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|