Export limit exceeded: 372194 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372194 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-40567 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| Segmentation fault vulnerability exists in Gpac through 1.0.1 via the gf_odf_size_descriptor function in desc_private.c when using mp4box, which causes a denial of service. | ||||
| CVE-2021-40566 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| A Segmentation fault casued by heap use after free vulnerability exists in Gpac through 1.0.1 via the mpgviddmx_process function in reframe_mpgvid.c when using mp4box, which causes a denial of service. | ||||
| CVE-2021-40565 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| A Segmentation fault caused by a null pointer dereference vulnerability exists in Gpac through 1.0.1 via the gf_avc_parse_nalu function in av_parsers.c when using mp4box, which causes a denial of service. | ||||
| CVE-2021-40564 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avc_parse_slice function in av_parsers.c when using mp4box, which causes a denial of service. | ||||
| CVE-2021-40563 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| A Segmentation fault exists casued by null pointer dereference exists in Gpac through 1.0.1 via the naludmx_create_avc_decoder_config function in reframe_nalu.c when using mp4box, which causes a denial of service. | ||||
| CVE-2021-40562 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service. | ||||
| CVE-2021-40559 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| A null pointer deference vulnerability exists in gpac through 1.0.1 via the naludmx_parse_nal_avc function in reframe_nalu, which allows a denail of service. | ||||
| CVE-2021-40556 | 1 Asus | 2 Rt-ax56u, Rt-ax56u Firmware | 2024-11-21 | 8.8 High |
| A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the strcat function called by "caupload" input handle function allowing the user to enter 0xFFFF bytes into the stack. This vulnerability allows an attacker to execute commands remotely. The vulnerability requires authentication. | ||||
| CVE-2021-40553 | 1 Piwigo | 1 Piwigo | 2024-11-21 | 8.8 High |
| piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor. | ||||
| CVE-2021-40546 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2024-11-21 | 4.9 Medium |
| Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi. | ||||
| CVE-2021-40543 | 1 Os4ed | 1 Opensis | 2024-11-21 | 9.8 Critical |
| Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file. | ||||
| CVE-2021-40542 | 1 Os4ed | 1 Opensis | 2024-11-21 | 6.1 Medium |
| Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php. | ||||
| CVE-2021-40541 | 1 Php-fusion | 1 Phpfusion | 2024-11-21 | 6.1 Medium |
| PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text. | ||||
| CVE-2021-40540 | 1 Ulfius Project | 1 Ulfius | 2024-11-21 | 9.8 Critical |
| ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check for certain malformed HTTP requests. | ||||
| CVE-2021-40537 | 1 Owncloud | 1 User Ldap | 2024-11-21 | 2.7 Low |
| Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap app. Administration role is necessary for exploitation. | ||||
| CVE-2021-40532 | 1 Telegram | 1 Web K Alpha | 2024-11-21 | 9.8 Critical |
| Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension. | ||||
| CVE-2021-40531 | 2 Apple, Sketch | 2 Macos, Sketch | 2024-11-21 | 9.8 Critical |
| Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app. | ||||
| CVE-2021-40530 | 2 Cryptopp, Fedoraproject | 2 Crypto\+\+, Fedora | 2024-11-21 | 5.9 Medium |
| The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP. | ||||
| CVE-2021-40529 | 3 Botan Project, Fedoraproject, Mozilla | 3 Botan, Fedora, Thunderbird | 2024-11-21 | 5.9 Medium |
| The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP. | ||||
| CVE-2021-40527 | 1 Onepeloton | 1 Peloton | 2024-11-21 | 8.6 High |
| Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the mobile application. | ||||