Show filters
1,213 Total Results
Displaying 61-70 of 1,213
Sort by:
Attacker Value
Unknown

CVE-2021-3551

Disclosure Date: February 16, 2022 (last updated October 07, 2023)
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
Attacker Value
Unknown

CVE-2021-3622

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-3672

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Attacker Value
Unknown

CVE-2021-44026

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
Attacker Value
Unknown

CVE-2021-44025

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
Attacker Value
Unknown

CVE-2021-42386

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function
Attacker Value
Unknown

CVE-2021-42385

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
Attacker Value
Unknown

CVE-2021-42384

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function
Attacker Value
Unknown

CVE-2021-42383

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
Attacker Value
Unknown

CVE-2021-42382

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function