Show filters
1,988 Total Results
Displaying 681-690 of 1,988
Sort by:
Attacker Value
Unknown

CVE-2021-3731

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
Attacker Value
Unknown

CVE-2021-3694

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
Attacker Value
Unknown

CVE-2021-38604

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
Attacker Value
Unknown

CVE-2021-33707

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.
Attacker Value
Unknown

CVE-2021-37180

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library lacks proper validation while parsing user-supplied OBJ files that could cause an out of bounds access to an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13775)
Attacker Value
Unknown

CVE-2021-37178

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying XML parser could cause the affected application to disclose arbitrary files to remote attackers by loading a specially crafted xml file.
Attacker Value
Unknown

CVE-2021-37179

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library in affected application lacks proper validation while parsing user-supplied OBJ files that could lead to a use-after-free condition. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13777)
Attacker Value
Unknown

CVE-2015-2073

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname, aka SAP Note 2018682.
Attacker Value
Unknown

CVE-2014-9320

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.
Attacker Value
Unknown

CVE-2015-2074

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681.