LiveActive security incident?Get immediate response
CVE archive

July 2021

Browse CVE records published in July 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1517 matching CVEs · Page 15 of 31.

Unknown · CVSS Not scored

CVE-2021-36373: Apache Ant TAR archive denial of service vulnerability

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Published Jul 14, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36386: report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_lis...

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

Published Jul 29, 2021 · Updated Aug 4, 2024

High · CVSS 8.1

CVE-2021-36367: PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authen...

PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).

Published Jul 9, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36374: Apache Ant ZIP, and ZIP based, archive denial of service vulerability

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Published Jul 14, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36383: Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demons...

Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as VMs, Backups, Audit, Users, and Groups.

Published Jul 12, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36371: Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certifi...

Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certificate requirements (i.e., mTLS cert_required) on backend upstreams when more than one TLSContext is defined and at least one configuration exists that does not require client certificate authentication. The attacker must send an SNI specifying an unprotected backend and an HTTP Host header specifying a protected backend. (2.x versions are unaffected. 1.x versions are unaffected with certain configuration settings involving prune_unreachable_routes and a wildcard Host resource.)

Published Jul 9, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36124: An issue was discovered in Echo ShareCare 8.15.5.

An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks such as SQL injection.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36123: An issue was discovered in Echo ShareCare 8.15.5.

An issue was discovered in Echo ShareCare 8.15.5. The TextReader feature in General/TextReader/TextReader.cfm is susceptible to a local file inclusion vulnerability when processing remote input in the textFile parameter from an authenticated user, leading to the ability to read arbitrary files on the server filesystems as well any files accessible via Universal Naming Convention (UNC) paths.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36126: An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36.

An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be invalid on a wiki. This would result in a fatal error, and potentially fail to block or restrict a potentially nefarious user.

Published Jul 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36090: Apache Commons Compress 1.0 to 1.20 denial of service vulnerability

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36121: An issue was discovered in Echo ShareCare 8.15.5.

An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via the name1 parameter, when processing remote input from an authenticated user, leading to the ability for arbitrary files to be written to arbitrary filesystem locations via ../ Directory Traversal on the Z: drive (a hard-coded drive letter where ShareCare application files reside) and remote code execution as the ShareCare service user (NT AUTHORITY\SYSTEM).

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36132: An issue was discovered in the FileImporter extension in MediaWiki through 1.36.

An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform.

Published Jul 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-36122: An issue was discovered in Echo ShareCare 8.15.5.

An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated user, leading to the ability to inject arbitrary arguments to 7z.exe.

Published Jul 13, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35472: An issue was discovered in LemonLDAP::NG before 2.0.12.

An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.

Published Jul 27, 2021 · Updated Aug 4, 2024