Unknown · CVSS Not scored
An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitrary code via proc-macros, and otherwise has no legitimate purpose.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13, on systems with perf_event_paranoid=-1 and no specific PMU driver support registered, allows local users to cause a denial of service (perf_instruction_pointer NULL pointer dereference and OOPS) via a "perf record" command.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers to cause a denial of service (NULL pointer dereference in the radiotap parser) by injecting a frame with 802.11a rates.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted.
Published Aug 21, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior
Published Aug 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR archive.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the FieldVar::mul_by_inverse method. Thus, a prover can produce a proof that is unsound but is nonetheless verified.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. In Decoder::new(), slice.get_unchecked(slice.length()) is used unsafely.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.
Published Aug 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order, aka an overflow.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.
Published Aug 29, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> sequences and then inject arbitrary SMTP commands.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.
Published Aug 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.
Published Aug 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
Published Aug 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a form via the submission_id parameter, e.g., clients/forms/edit_submission.php?form_id=1&view_id=1&submission_id=[XSS].
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible for the customer to log in and proceed with a change of name and last name. However, these fields are vulnerable to XSS payload insertion, being triggered in the admin panel when the admin tries to see the client list. This type of XSS (stored) can lead to the extraction of the PHPSESSID cookie belonging to the admin.
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; however, XSS protection is planned for a future release.
Published Aug 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user().
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.
Published Aug 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the /it-IT/splunkd/__raw/services/get_snapshot HTTP API endpoint. A ‘low privileged’ attacker can read any file on the target host.
Published Aug 6, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-2013-0868.
Published Aug 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The REST API in Planview Spigit 4.5.3 allows remote unauthenticated attackers to query sensitive user accounts data, as demonstrated by an api/v1/users/1 request.
Published Aug 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.
Published Aug 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when running workflows, an attacker may be able to disrupt a workflow because expression template output is evaluated.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Joplin before 2.0.9 allows XSS via button and form in the note body.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame data. A successful exploit could allow the attacker to perform a clickjacking attack where the user is tricked into clicking a malicious link.
Published Aug 9, 2021 · Updated Aug 4, 2024
High · CVSS 7.1
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
Published Aug 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api/addbouquet?name=) leads to Stored XSS.
Published Aug 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the POP3 STLS command, injecting plaintext commands into an encrypted user session.
Published Aug 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYSTEM process resulting in escalation of privileges. This occurs because the driver drops a world-writable DLL into a CanonBJ %PROGRAMDATA% location that gets loaded by printisolationhost (a system process).
Published Aug 11, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash comparison.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
Published Aug 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for /webssh (the victim must have configured Terminal with at least one host). Successful exploitation depends on the browser used by a potential victim (e.g., exploitation can occur with Firefox but not Chrome).
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.
Published Aug 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
crypto/digest.c in Pengutronix barebox through 2021.07.0 leaks timing information because memcmp is used during digest verification.
Published Aug 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
Published Aug 23, 2021 · Updated Aug 4, 2024
Critical · CVSS 9.8
The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6.6, 4.0.12, 5.0.5; for Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5; for Bamboo 2.5.9, 3.6.6, 4.0.12, 5.0.5; and for Fisheye 2.5.9.
Published Aug 2, 2021 · Updated Aug 4, 2024