LiveActive security incident?Get immediate response
CVE archive

August 2021

Browse CVE records published in August 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2047 matching CVEs · Page 30 of 41.

Unknown · CVSS Not scored

CVE-2021-30070: An issue was discovered in HestiaCP before v1.3.5.

An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being transmitted to the operating system's package manager.

Published Aug 18, 2022 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29984: Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly...

Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.

Published Aug 17, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29989: Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12.

Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.13, Firefox ESR < 78.13, and Firefox < 91.

Published Aug 17, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29987: After requesting multiple permissions, and closing the first permission panel, subsequent permission panels...

After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible to trick a user into accepting a permission they did not want to. *This bug only affects Firefox on Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91 and Thunderbird < 91.

Published Aug 17, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29974: When network partitioning was enabled, e.g.

When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically. This vulnerability affects Firefox < 90.

Published Aug 5, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29973: Password autofill was enabled without user interaction on insecure websites on Firefox for Android.

Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interaction with the page before a user's password would be entered by the browser's autofill functionality *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 90.

Published Aug 5, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29986: A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable...

A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.

Published Aug 17, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29976: Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird.

Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.

Published Aug 5, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29969: If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server...

If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS handshake, then Thunderbird didn't ignore the injected data. This could have resulted in Thunderbird showing incorrect information, for example the attacker could have tricked Thunderbird to show folders that didn't exist on the IMAP server. This vulnerability affects Thunderbird < 78.12.

Published Aug 5, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29631: In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399,...

In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O descriptors. A malicious guest may cause the device model to operate on uninitialized I/O vectors leading to memory corruption, crashing of the bhyve process, and possibly arbitrary code execution in the bhyve process.

Published Aug 30, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29630: In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381,...

In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, the ggatec daemon does not validate the size of a response before writing it to a fixed-sized buffer allowing a malicious attacker in a privileged network position to overwrite the stack of ggatec and potentially execute arbitrary code.

Published Aug 30, 2021 · Updated Aug 3, 2024

High · CVSS 7.4

CVE-2021-29487: Authentication bypass in Octobercms

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request. This only affects frontend users and the attacker must obtain a Laravel secret key for cookie encryption and signing in order to exploit this vulnerability. The issue has been patched in Build 472 and v1.1.5.

Published Aug 26, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-29294: Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicio...

Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicious user cause a denial of service via the send_hnap_unauthorized function. It could be triggered by sending crafted POST request to /HNAP1/. NOTE: The DSL-2740R and all hardware revisions are considered End of Life and as such this issue will not be patched

Published Aug 10, 2021 · Updated Aug 3, 2024