Show filters
192 Total Results
Displaying 81-90 of 192
Sort by:
Attacker Value
Unknown
CVE-2021-46142
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
0
Attacker Value
Unknown
CVE-2021-46141
Disclosure Date: January 06, 2022 (last updated February 23, 2025)
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
0
Attacker Value
Unknown
CVE-2021-23727
Disclosure Date: December 29, 2021 (last updated February 23, 2025)
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.
0
Attacker Value
Unknown
CVE-2021-43560
Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
0
Attacker Value
Unknown
CVE-2021-43559
Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
0
Attacker Value
Unknown
CVE-2021-43558
Disclosure Date: November 22, 2021 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
0
Attacker Value
Unknown
CVE-2021-21897
Disclosure Date: September 08, 2021 (last updated February 23, 2025)
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-38714
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
0
Attacker Value
Unknown
CVE-2021-20247
Disclosure Date: February 23, 2021 (last updated February 22, 2025)
A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest threat from this vulnerability is to data confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2021-23926
Disclosure Date: January 14, 2021 (last updated February 22, 2025)
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
0