LiveActive security incident?Get immediate response
CVE archive

July 2021

Browse CVE records published in July 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1517 matching CVEs · Page 18 of 31.

Unknown · CVSS Not scored

CVE-2021-35207: An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch...

An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the login component of Zimbra Web Client, in which an attacker can execute arbitrary JavaScript by adding executable JavaScript to the loginErrorCode parameter of the login url.

Published Jul 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35208: An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite...

An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

Published Jul 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35193: Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authenticat...

Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across different customers' installations (that have the same software version). This provides remote access to SQL database credentials. (In the normal use of the product, retrieving those credentials only occurs after a username/password authentication step; however, this authentication step is on the client side, and an attacker can develop their own client that skips this step.)

Published Jul 30, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35209: An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before...

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied requests. The value of X-Host header is not checked against the whitelist of hosts Zimbra is allowed to proxy to (the zimbraProxyAllowedDomains setting).

Published Jul 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-35037: Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers w...

Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An attacker may craft a URL that appears to be for a customer's Jamf Pro instance, but when clicked will forward a user to an arbitrary URL that may be malicious. This is tracked via Jamf with the following ID: PI-009822

Published Jul 12, 2021 · Updated Aug 4, 2024

High · CVSS 8.2

CVE-2021-34987: This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Des...

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the HDAudio virtual device. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-14969.

Published Jul 15, 2022 · Updated Aug 4, 2024

High · CVSS 7.8

CVE-2021-34986: This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Des...

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Parallels Service. By creating a symbolic link, an attacker can abuse the service to execute a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-13932.

Published Jul 15, 2022 · Updated Aug 4, 2024

High · CVSS 8.8

CVE-2021-34827: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of...

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the SOAPAction HTTP header. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-12029.

Published Jul 15, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34820: Web Path Directory Traversal in the Novus HTTP Server.

Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for Arbitrary File Access vulnerability. A remote, unauthenticated attacker using an HTTP GET request may be able to exploit this issue to access sensitive data. The issue was discovered in the NMS (Novus Management System) software through 1.51.2

Published Jul 19, 2021 · Updated Aug 4, 2024

High · CVSS 8.8

CVE-2021-34830: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of...

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the Cookie HTTP header. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-12028.

Published Jul 15, 2021 · Updated Aug 4, 2024

High · CVSS 8.8

CVE-2021-34829: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of...

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the HNAP_AUTH HTTP header. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-12065.

Published Jul 15, 2021 · Updated Aug 4, 2024

High · CVSS 8.8

CVE-2021-34828: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of...

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the SOAPAction HTTP header. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-12066.

Published Jul 15, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34821: Cross Site Scripting (XSS) vulnerability exists in AAT Novus Management System through 1.51.2.

Cross Site Scripting (XSS) vulnerability exists in AAT Novus Management System through 1.51.2. The WebUI has wrong HTTP 404 error handling implemented. A remote, unauthenticated attacker may be able to exploit the issue by sending malicious HTTP requests to non-existing URIs. The value of the URL path filename is copied into the HTML document as plain text tags.

Published Jul 19, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34807: An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0.

An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker could redirect a user to any URL via isredirect=1&redirectURL= in conjunction with the token data (e.g., a valid authtoken= value).

Published Jul 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34617: A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) p...

A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.13 and below; Aruba Instant 6.5.x: 6.5.4.13 and below; Aruba Instant 8.3.x: 8.3.0.7 and below; Aruba Instant 8.4.x: 8.4.0.5 and below; Aruba Instant 8.5.x: 8.5.0.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

Published Jul 19, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34688: iDrive RemotePC before 7.6.48 on Windows allows information disclosure.

iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key and is therefore reversible by an attacker.

Published Jul 15, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34687: iDrive RemotePC before 7.6.48 on Windows allows information disclosure.

iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher.

Published Jul 15, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-34618: A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) prod...

A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.4.x: All versions; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

Published Jul 19, 2021 · Updated Aug 4, 2024