CVE-2021-31176: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Published May 11, 2021 · Updated Aug 3, 2024
Browse CVE records published in May 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 1909 matching CVEs · Page 27 of 39.
Microsoft Office Remote Code Execution Vulnerability
Published May 11, 2021 · Updated Aug 3, 2024
Windows Container Manager Service Elevation of Privilege Vulnerability
Published May 11, 2021 · Updated Aug 3, 2024
Visual Studio Code Remote Code Execution Vulnerability
Published May 11, 2021 · Updated Aug 3, 2024
Windows SSDP Service Elevation of Privilege Vulnerability
Published May 11, 2021 · Updated Aug 3, 2024
Visual Studio Code Remote Code Execution Vulnerability
Published May 11, 2021 · Updated Aug 3, 2024
Windows Desktop Bridge Denial of Service Vulnerability
Published May 11, 2021 · Updated Aug 3, 2024
In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly checking the user's permissions, allowing read-access to resources beyond what those users were explicitly allowed to access.
Published May 19, 2021 · Updated Aug 3, 2024
please before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option.
Published May 27, 2021 · Updated Aug 3, 2024
pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.
Published May 27, 2021 · Updated Aug 3, 2024
Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are allowed to execute at least one command.
Published May 27, 2021 · Updated Aug 3, 2024
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.
Published May 26, 2021 · Updated Aug 3, 2024
A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.
Published May 26, 2021 · Updated Aug 3, 2024
The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.
Published May 11, 2022 · Updated Aug 3, 2024
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
Published May 11, 2021 · Updated Aug 3, 2024
A flaw was found in PoDoFo 0.9.7. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because of a improper check of the keyLength value.
Published May 26, 2021 · Updated Aug 3, 2024
In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly
Published May 11, 2021 · Updated Aug 3, 2024
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.
Published May 26, 2021 · Updated Aug 3, 2024
Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.
Published May 26, 2021 · Updated Aug 3, 2024
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
Published May 6, 2021 · Updated Aug 3, 2024
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.
Published May 29, 2021 · Updated Aug 3, 2024
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.
Published May 26, 2021 · Updated Aug 3, 2024
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.
Published May 27, 2021 · Updated Aug 3, 2024
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.
Published May 14, 2021 · Updated Aug 3, 2024
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signup/update' via the 'surname' parameter.
Published May 12, 2021 · Updated Aug 3, 2024
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
Published May 25, 2021 · Updated Aug 3, 2024
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
Published May 25, 2021 · Updated Aug 3, 2024
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.
Published May 12, 2021 · Updated Aug 3, 2024
Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code.
Published May 29, 2021 · Updated Aug 3, 2024
Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.
Published May 31, 2021 · Updated Aug 3, 2024
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
Published May 25, 2021 · Updated Aug 3, 2024
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
Published May 25, 2021 · Updated Aug 3, 2024
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
Published May 11, 2021 · Updated Aug 3, 2024
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
Published May 25, 2021 · Updated Aug 3, 2024
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
Published May 25, 2021 · Updated Aug 3, 2024
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are handled by the GenericFilter which will find the service and method specified in the first arguments of the invocation and use the Java Reflection API to make the final call. The signature for the $invoke or $invokeAsync methods is Ljava/lang/String;[Ljava/lang/String;[Ljava/lang/Object; where the first argument is the name of the method to invoke, the second one is an array with the parameter types for the method being invoked and the third one is an array with the actual call arguments. In addition, the caller also needs to set an RPC attachment specifying that the call is a generic call and how to decode the arguments. The possible values are: - true - raw.return - nativejava - bean - protobuf-json An attacker can control this RPC attachment and set it to nativejava to force the java deserialization of the byte array located in the third argument.
Published May 31, 2021 · Updated Aug 3, 2024
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
Published May 25, 2021 · Updated Aug 3, 2024
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/documentnotes/saveNote' via the 'nota' parameter.
Published May 12, 2021 · Updated Aug 3, 2024
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
Published May 25, 2021 · Updated Aug 3, 2024
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.
Published May 12, 2021 · Updated Aug 3, 2024
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
Published May 25, 2021 · Updated Aug 3, 2024
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
Published May 25, 2021 · Updated Aug 3, 2024
A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.
Published May 18, 2021 · Updated Aug 3, 2024
An issue was discovered in Mediat 1.4.1. There is a Reflected XSS vulnerability which allows remote attackers to inject arbitrary web script or HTML without authentication via the 'return' parameter in login.php.
Published May 24, 2021 · Updated Aug 3, 2024
Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it.
Published May 24, 2021 · Updated Aug 3, 2024
An issue was discovered in Gris CMS v0.1. There is a Persistent XSS vulnerability which allows remote attackers to inject arbitrary web script or HTML via admin/dashboard.
Published May 24, 2021 · Updated Aug 3, 2024
SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.
Published May 20, 2022 · Updated Aug 3, 2024
An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive data via admin/navbar.php?action=add_page.
Published May 24, 2021 · Updated Aug 3, 2024
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
Published May 11, 2021 · Updated Aug 3, 2024
ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Secondary, the retrieval of all users on a large instance could cause higher than average load on the instance.
Published May 20, 2021 · Updated Aug 3, 2024
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in Eigen implementation of `tf.raw_ops.BandedTriangularSolve`. The implementation(https://github.com/tensorflow/tensorflow/blob/eccb7ec454e6617738554a255d77f08e60ee0808/tensorflow/core/kernels/linalg/banded_triangular_solve_op.cc#L269-L278) calls `ValidateInputTensors` for input validation but fails to validate that the two tensors are not empty. Furthermore, since `OP_REQUIRES` macro only stops execution of current function after setting `ctx->status()` to a non-OK value, callers of helper functions that use `OP_REQUIRES` must check value of `ctx->status()` before continuing. This doesn't happen in this op's implementation(https://github.com/tensorflow/tensorflow/blob/eccb7ec454e6617738554a255d77f08e60ee0808/tensorflow/core/kernels/linalg/banded_triangular_solve_op.cc#L219), hence the validation that is present is also not effective. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow 2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range.
Published May 14, 2021 · Updated Aug 3, 2024