Unknown · CVSS Not scored
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
Published Jul 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Published Jul 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.
Published Jul 29, 2021 · Updated Aug 4, 2024
High · CVSS 8.1
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
Published Jul 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory.
Published Jul 13, 2021 · Updated Aug 4, 2024
Low · CVSS 2.6
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
Published Jul 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Published Jul 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
Published Jul 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as VMs, Backups, Audit, Users, and Groups.
Published Jul 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_error= on the login screen of the Web application.
Published Jul 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certificate requirements (i.e., mTLS cert_required) on backend upstreams when more than one TLSContext is defined and at least one configuration exists that does not require client certificate authentication. The attacker must send an SNI specifying an unprotected backend and an HTTP Host header specifying a protected backend. (2.x versions are unaffected. 1.x versions are unaffected with certain configuration settings involving prune_unreachable_routes and a wildcard Host resource.)
Published Jul 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.
Published Jul 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
Published Jul 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.
Published Jul 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.
Published Jul 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
Published Jul 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ACRN before 2.5 has a hw/pci/virtio/virtio.c vq_endchains NULL Pointer Dereference.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which, for a suppressed MediaWiki user, were different than for any other user, thus easily disclosing suppressed accounts (which are supposed to be completely hidden).
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks such as SQL injection.
Published Jul 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny service by sending malformed requests.
Published Jul 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/pci/virtio/*.c.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Echo ShareCare 8.15.5. The TextReader feature in General/TextReader/TextReader.cfm is susceptible to a local file inclusion vulnerability when processing remote input in the textFile parameter from an authenticated user, leading to the ability to read arbitrary files on the server filesystems as well any files accessible via Universal Naming Convention (UNC) paths.
Published Jul 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour).
Published Jul 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE.
Published Jul 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in ACRN before 2.5. It allows a devicemodel/hw/pci/virtio/virtio_net.c virtio_net_ping_rxq NULL pointer dereference for vq->used.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.
Published Jul 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be invalid on a wiki. This would result in a fatal error, and potentially fail to block or restrict a potentially nefarious user.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data fields. The attack could easily propagate across many pages for many users.
Published Jul 2, 2021 · Updated Aug 4, 2024
Critical · CVSS 9.8
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).
Published Jul 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
Published Jul 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in ACRN before 2.5. dmar_free_irte in hypervisor/arch/x86/vtd.c allows an irte_alloc_bitmap buffer overflow.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via the name1 parameter, when processing remote input from an authenticated user, leading to the ability for arbitrary files to be written to arbitrary filesystem locations via ../ Directory Traversal on the Z: drive (a hard-coded drive letter where ShareCare application files reside) and remote code execution as the ShareCare service user (NT AUTHORITY\SYSTEM).
Published Jul 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).
Published Jul 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ACRN before 2.5 has a devicemodel/hw/pci/xhci.c NULL Pointer Dereference for a trb pointer.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a single HTTP/2 frame, leading to Uncontrolled Recursion and stack consumption.
Published Jul 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does not validate the parameter for aggregategroup when action=remove is set, thus allowing users with the translate-manage right to silently delete various groups' metadata.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated user, leading to the ability to inject arbitrary arguments to 7z.exe.
Published Jul 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.
Published Jul 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a privileged user could inject arbitrary HTML and JavaScript within various data fields. The attack could easily propagate across many pages for many users.
Published Jul 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.
Published Jul 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones.
Published Jul 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows remote authenticated attackers to achieve denial of services and information disclosure via TCP/IP packets.
Published Jul 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
Published Jul 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authenticated attackers to achieve code execution, denial of services, and information disclosure via serial ports.
Published Jul 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.
Published Jul 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page.
Published Jul 27, 2021 · Updated Aug 4, 2024