Total
32365 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-33667 | 1 Sap | 1 Businessobjects Web Intelligence | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend application, which would otherwise be restricted. | |||||
CVE-2021-33663 | 1 Sap | 1 Netweaver Application Server Abap | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attacker to insert cleartext commands due to improper restriction of I/O buffering into encrypted SMTP sessions over the network which can partially impact the integrity of the application. | |||||
CVE-2021-33662 | 1 Sap | 1 Business One | 2024-11-21 | 2.1 LOW | 4.4 MEDIUM |
Under certain conditions, the installation of SAP Business One, version - 10.0, discloses sensitive information on the file system allowing an attacker to access information which would otherwise be restricted. | |||||
CVE-2021-33638 | 1 Openeuler | 1 Isula | 2024-11-21 | N/A | 8.4 HIGH |
When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container. | |||||
CVE-2021-33637 | 1 Openeuler | 1 Isula | 2024-11-21 | N/A | 8.4 HIGH |
When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container. | |||||
CVE-2021-33636 | 1 Openeuler | 1 Isula | 2024-11-21 | N/A | 8.4 HIGH |
When the isula load command is used to load malicious images, attackers can execute arbitrary code. | |||||
CVE-2021-33635 | 1 Openeuler | 1 Isula | 2024-11-21 | N/A | 9.8 CRITICAL |
When malicious images are pulled by isula pull, attackers can execute arbitrary code. | |||||
CVE-2021-33634 | 1 Openeuler | 1 Icr | 2024-11-21 | N/A | 6.3 MEDIUM |
iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS. | |||||
CVE-2021-33617 | 1 Zohocorp | 1 Manageengine Password Manager Pro | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid. | |||||
CVE-2021-33603 | 3 Apple, F-secure, Microsoft | 9 Macos, Atlant, Cloud Protection For Salesforce and 6 more | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine. | |||||
CVE-2021-33602 | 1 F-secure | 4 Atlant, Cloud Protection, Internet Gatekeeper and 1 more | 2024-11-21 | 5.0 MEDIUM | 5.5 MEDIUM |
A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZW decompression method), and this can crash the scanning engine. The vulnerability can be exploited remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine. | |||||
CVE-2021-33601 | 1 F-secure | 1 Internet Gatekeeper | 2024-11-21 | 6.5 MEDIUM | 7.6 HIGH |
A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server. | |||||
CVE-2021-33598 | 3 Apple, F-secure, Microsoft | 5 Macos, Atlant, Elements Endpoint Protection and 2 more | 2024-11-21 | 4.0 MEDIUM | 4.6 MEDIUM |
A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine. | |||||
CVE-2021-33597 | 3 Apple, F-secure, Microsoft | 6 Macos, Business Suite, Client Security and 3 more | 2024-11-21 | 4.3 MEDIUM | 3.5 LOW |
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine. | |||||
CVE-2021-33587 | 2 Css-what Project, Netapp | 2 Css-what, E-series Performance Analyzer | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input. | |||||
CVE-2021-33575 | 1 Pixar | 1 Ruby-jss | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing. | |||||
CVE-2021-33558 | 1 Boa | 1 Boa | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa. | |||||
CVE-2021-33523 | 1 Softwareag | 1 Mashzone Nextgen | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can execute arbitrary commands on the underlying host. This occurs in com.idsscheer.ppmmashup.business.jdbc.DriverUploadController. | |||||
CVE-2021-33500 | 2 Microsoft, Putty | 2 Windows, Putty | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. NOTE: the same attack methodology may affect some OS-level GUIs on Linux or other platforms for similar reasons. | |||||
CVE-2021-33436 | 2 Microsoft, Nomachine | 2 Windows, Nomachine | 2024-11-21 | 6.2 MEDIUM | 7.3 HIGH |
NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITY\SYSTEM. |