Show filters
940 Total Results
Displaying 461-470 of 940
Sort by:
Attacker Value
Unknown
CVE-2021-35515
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
0
Attacker Value
Unknown
CVE-2021-20461
Disclosure Date: June 29, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.
0
Attacker Value
Unknown
CVE-2021-22901
Disclosure Date: June 11, 2021 (last updated February 22, 2025)
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the corr…
0
Attacker Value
Unknown
CVE-2021-20293
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces MediaType. This flaw allows an attacker to launch a reflected XSS attack. The highest threat from this vulnerability is to data confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2021-3522
Disclosure Date: June 02, 2021 (last updated February 22, 2025)
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
0
Attacker Value
Unknown
CVE-2020-14326
Disclosure Date: June 02, 2021 (last updated February 22, 2025)
A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with higher CPU time spent searching and adding the entry. This flaw allows an attacker to cause a denial of service.
0
Attacker Value
Unknown
CVE-2020-10771
Disclosure Date: June 02, 2021 (last updated February 22, 2025)
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
0
Attacker Value
Unknown
CVE-2019-4722
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due to mishandling of certain error conditions. IBM X-Force ID: 172128.
0
Attacker Value
Unknown
CVE-2020-4520
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.
0
Attacker Value
Unknown
CVE-2020-4561
Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM X-Force ID: 183903.
0