Show filters
978 Total Results
Displaying 271-280 of 978
Sort by:
Attacker Value
Unknown
CVE-2021-42376
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
0
Attacker Value
Unknown
CVE-2021-42375
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
0
Attacker Value
Unknown
CVE-2021-42374
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
0
Attacker Value
Unknown
CVE-2021-42373
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
0
Attacker Value
Unknown
CVE-2017-5123
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
0
Attacker Value
Unknown
CVE-2020-35249
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature.
0
Attacker Value
Unknown
CVE-2021-25219
Disclosure Date: October 27, 2021 (last updated November 08, 2023)
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.
0
Attacker Value
Unknown
CVE-2020-23042
Disclosure Date: October 22, 2021 (last updated February 23, 2025)
Dropouts Technologies LLP Super Backup v2.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability in the path parameter of the `list` and `download` module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted GET request.
0
Attacker Value
Unknown
CVE-2020-23061
Disclosure Date: October 22, 2021 (last updated February 23, 2025)
Dropouts Technologies LLP Super Backup v2.0.5 was discovered to contain an issue in the path parameter of the `list` and `download` module which allows attackers to perform a directory traversal via a change to the path variable to request the local list command.
0
Attacker Value
Unknown
CVE-2021-41524
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
0