Unknown · CVSS Not scored
Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
Published Mar 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in IdentityModel (aka ScottBrady.IdentityModel) before 1.3.0. The Branca implementation allows an attacker to modify and forge authentication tokens.
Published Mar 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.
Published Mar 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
Published Mar 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.
Published Mar 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
Published Mar 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
Published Mar 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zoho ManageEngine ADManager Plus before 7066 allows XSS.
Published Mar 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Published Mar 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published Mar 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.
Published Mar 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published Mar 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because of excessive logging.
Published Mar 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack.
Published Mar 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash.
Published Mar 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem
Published Mar 30, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.
Published Mar 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code.
Published Mar 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage.
Published Mar 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.
Published Mar 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuration.
Published Mar 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.
Published Mar 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php
Published Mar 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain administrative privileges.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the whitelist via the checkedList parameter to the delete command.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticated attackers to force a device reboot.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a denial of service attack.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.
Published Mar 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the language parameter.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in write requests, potentially allowing denial of service attacks.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.
Published Mar 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing attackers (with access to a network capture) to quickly generate multiple collisions to generate valid passwords, or infer some parts of the original.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to bypass access controls and obtain full control of the device.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Courier Management System 1.0 - 'First Name' Stored XSS
Published Mar 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices. Most of the integer parameters sent through the web server can be abused to cause a denial of service attack.
Published Mar 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communicate with the MobileIron SaaS discovery API, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in com/mobileiron/registration/RegisterActivity.java and can be used for api/v1/gateway/customers/servers requests. NOTE: Vendor states that this is an opt-in feature to the product - it is not enabled by default and customers cannot enable it without an explicit email to support. At this time, they do not plan change to make any changes to this feature.
Published Mar 29, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in the com/mobileiron/common/utils/C4928m.java file. NOTE: It has been asserted that there is no causality or connection between credential encryption and the MiTM attack
Published Mar 29, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.
Published Mar 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
Published Mar 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
Published Mar 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
Published Mar 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4
Published Mar 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use another widely known key that is designed for testing purposes: "01030507090b0d0f00020406080a0c0d" (the decimal equivalent of 1 3 5 7 9 11 13 15 0 2 4 6 8 10 12 13), which is human generated and static across all issued devices.
Published Mar 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
Published Mar 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
Published Mar 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.
Published Mar 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /pages/delete/3.
Published Mar 10, 2021 · Updated Aug 4, 2024