LiveActive security incident?Get immediate response
CVE archive

August 2021

Browse CVE records published in August 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2047 matching CVEs · Page 26 of 41.

Unknown · CVSS Not scored

CVE-2021-32066: An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1.

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

Published Aug 1, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-32068: The AWV and MiCollab Client Service components in Mitel MiCollab before 9.3 could allow an attacker to perf...

The AWV and MiCollab Client Service components in Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack by sending multiple session renegotiation requests, due to insufficient TLS session controls. A successful exploit could allow an attacker to modify application data and state.

Published Aug 13, 2021 · Updated Aug 3, 2024

High · CVSS 7.8

CVE-2021-31504: This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText...

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12691.

Published Aug 3, 2021 · Updated Aug 3, 2024

High · CVSS 7.8

CVE-2021-31503: This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText...

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IGS files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12690.

Published Aug 3, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31566: An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, ac...

An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.

Published Aug 23, 2022 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31400: An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1.

An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-data processing function invokes a panic function if the pointer to the end of the out-of-band data points outside of the TCP segment's data. If the panic function hadn't a trap invocation removed, it will enter an infinite loop and therefore cause DoS (continuous loop or a device reset).

Published Aug 19, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31401: An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1.

An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn't sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet.

Published Aug 19, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31228: An issue was discovered in HCC embedded InterNiche 4.0.1.

An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to the DNS client's requests (without sniffing the specific request). Data is predictable because it is based on the time of day, and has too few bits.

Published Aug 19, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31227: An issue was discovered in HCC embedded InterNiche 4.0.1.

An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parses the HTTP POST request, due to an incorrect signed integer comparison. This vulnerability requires the attacker to send a malformed HTTP packet with a negative Content-Length, which bypasses the size checks and results in a large heap overflow in the wbs_multidata buffer copy.

Published Aug 19, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-31226: An issue was discovered in HCC embedded InterNiche 4.0.1.

An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parses the HTTP POST request, due to lack of size validation. This vulnerability requires the attacker to send a crafted HTTP POST request with a URI longer than 50 bytes. This leads to a heap overflow in wbs_post() via an strcpy() call.

Published Aug 19, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-30941: A buffer overflow issue was addressed with improved memory handling.

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina. Processing a maliciously crafted USD file may disclose memory contents.

Published Aug 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-30984: A race condition was addressed with improved state handling.

A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

Published Aug 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-30995: A race condition was addressed with improved state handling.

A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to elevate privileges.

Published Aug 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-30958: An out-of-bounds read was addressed with improved input validation.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Playing a malicious audio file may lead to arbitrary code execution.

Published Aug 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-30965: A logic issue was addressed with improved state management.

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious application may be able to cause a denial of service to Endpoint Security clients.

Published Aug 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-30966: A logic issue was addressed with improved state management.

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. User traffic might unexpectedly be leaked to a proxy server despite PAC configurations.

Published Aug 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-30982: A race condition was addressed with improved locking.

A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A remote attacker may be able to cause unexpected application termination or heap corruption.

Published Aug 24, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-30956: A lock screen issue allowed access to contacts on a locked device.

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker with physical access to a device may be able to see private contact information.

Published Aug 24, 2021 · Updated Aug 3, 2024