LiveActive security incident?Get immediate response
CVE archive

July 2021

Browse CVE records published in July 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1517 matching CVEs · Page 13 of 31.

Critical · CVSS 10

CVE-2021-41037: In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine...

In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command-line used to start the application, injecting things like agent or other settings that usually require particular attention in term of security. Although p2 has built-in strategies to ensure artifacts are signed and then to help establish trust, there is no such strategy for the metadata part that does configure such touchpoints. As a result, it's possible to install a unit that will run malicious code during installation without user receiving any warning about this installation step being risky when coming from untrusted source.

Published Jul 8, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-40874: An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13.

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.

Published Jul 17, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37839: Improper access to dataset metadata information

Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.

Published Jul 6, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37600: An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker wer...

An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources in a way that leads to a large number in the /proc/sysvipc/sem file. NOTE: this is unexploitable in GNU C Library environments, and possibly in all realistic environments.

Published Jul 28, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37555: TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to...

TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g., tar and nc).

Published Jul 26, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37578: Remote code execution via RMI

Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI invocations. A remote attacker can send a malicious serialized object to the above RMI entries. The objects get deserialized without any check on the incoming data. In the worst case, it may let the attacker run arbitrary code remotely. For both jUDDI web service applications and jUDDI clients, the usage of RMI is disabled by default. Since this is an optional feature and an extension to the UDDI protocol, the likelihood of impact is low. Starting with 3.3.10, all RMI related code was removed.

Published Jul 29, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37593: PEEL Shopping version 9.4.0 allows remote SQL injection.

PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data.

Published Jul 27, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-37606: Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's...

Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attacker to infer collisions by measuring timing differences.

Published Jul 28, 2021 · Updated Aug 4, 2024