Show filters
1,078 Total Results
Displaying 211-220 of 1,078
Sort by:
Attacker Value
Unknown

CVE-2021-32952

Disclosure Date: June 17, 2021 (last updated February 22, 2025)
An out-of-bounds write issue exists in the DGN file-reading procedure in the Drawings SDK (Version 2022.4 and prior) resulting from the lack of proper validation of user-supplied data. This can result in a write past the end of an allocated buffer and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.
Attacker Value
Unknown

CVE-2021-32940

Disclosure Date: June 17, 2021 (last updated February 22, 2025)
An out-of-bounds read issue exists in the DWG file-recovering procedure in the Drawings SDK (All versions prior to 2022.5) resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allow attackers to cause a denial-of-service condition or read sensitive information from memory locations.
Attacker Value
Unknown

CVE-2021-32946

Disclosure Date: June 17, 2021 (last updated February 22, 2025)
An improper check for unusual or exceptional conditions issue exists within the parsing DGN files from Drawings SDK (Version 2022.4 and prior) resulting from the lack of proper validation of the user-supplied data. This may result in several of out-of-bounds problems and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.
Attacker Value
Unknown

CVE-2021-0001

Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2021-33669

Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For a successful exploitation user interaction from another user is required and could lead to complete impact of confidentiality integrity and availability.
Attacker Value
Unknown

CVE-2021-27434

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
Attacker Value
Unknown

CVE-2021-32622

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab. This only impacts the local user while in the process of uploading. It cannot be exploited remotely or by other users. This vulnerability is patched in version 3.21.0.
Attacker Value
Unknown

CVE-2021-22547

Disclosure Date: May 04, 2021 (last updated February 22, 2025)
In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in memory objects larger than the buffer and wrap around to have a smaller buffer than required, allowing the attacker access to the other parts of the heap. We recommend upgrading the Google Cloud IoT Device SDK for Embedded C used to 1.0.3 or greater.
Attacker Value
Unknown

CVE-2021-31784

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Drawings SDK before 2021.6 on all supported by ODA platforms in static configuration. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart) or possible code execution.
Attacker Value
Unknown

CVE-2021-21320

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.