LiveActive security incident?Get immediate response
CVE archive

June 2021

Browse CVE records published in June 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1730 matching CVEs · Page 14 of 35.

Critical · CVSS 9.8

CVE-2021-35081: Possible buffer overflow due to improper validation of SSID length received from beacon or probe response d...

Possible buffer overflow due to improper validation of SSID length received from beacon or probe response during an IBSS session in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

Published Jun 14, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35041: The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a...

The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A malicious node can send a packet continuously. The packet is in an incorrect format and cannot be decoded by the node correctly. As a result, the node may consume the memory sustainably and crash. More details are shown at: https://github.com/FISCO-BCOS/FISCO-BCOS/issues/1951

Published Jun 23, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34813: Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting t...

Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.

Published Jun 16, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34683: An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0.

An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/bbs/asp/get_user_email_info_bbs.asp to obtain the contact information (name and e-mail address) of everyone in the entire organization. This information can allow remote attackers to perform social engineering or brute force attacks against the system login page.

Published Jun 16, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34546: An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, tha...

An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and execute arbitrary commands as SYSTEM via the "save log to file" feature. To accomplish this, the attacker can navigate to cmd.exe.

Published Jun 10, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34539: An issue was discovered in CubeCoders AMP before 2.1.1.8.

An issue was discovered in CubeCoders AMP before 2.1.1.8. A lack of validation of the Java Version setting means that an unintended executable path can be set. The result is that high-privileged users can trigger code execution.

Published Jun 10, 2021 · Updated Aug 4, 2024

Low · CVSS 2.9

CVE-2021-34428: For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListe...

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

Published Jun 22, 2021 · Updated Aug 4, 2024

Medium · CVSS 6.3

CVE-2021-34387: The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission sett...

The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.

Published Jun 21, 2021 · Updated Aug 4, 2024