Base de données CVE
Archive des vulnérabilités connues (CVE) avec score CVSS, gravité, produits et éditeurs concernés. Filtrez par année et par sévérité.
- CVE-2021-28799Critique10.0
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
- CVE-2021-31207Moyenne6.6
Microsoft Exchange Server Security Feature Bypass Vulnerability
- CVE-2021-31166Critique9.8
HTTP Protocol Stack Remote Code Execution Vulnerability
- CVE-2021-28664Élevée8.8
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
- CVE-2021-28663Élevée8.8
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
- CVE-2021-31755Critique9.8
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
- CVE-2021-1906Moyenne6.2
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- CVE-2021-1905Élevée8.4
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- CVE-2021-32030Critique9.8
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.
- CVE-2021-1498Critique9.8
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-1497Critique9.8
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-21551Élevée8.8
Le pilote Dell dbutil_2_3.sys contient une vulnérabilité de contrôle d'accès insuffisant pouvant entraîner une élévation de privilèges, un déni de service ou une divulgation d'informations. Un accès utilisateur authentifié local est requis.
- CVE-2021-20090Critique9.8
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
- CVE-2021-29442Élevée8.6
Nacos est une plateforme conçue pour la découverte dynamique de services ainsi que la configuration et la gestion des services. Dans Nacos avant la version 1.4.1, le ConfigOpsController permet à l'utilisateur d'effectuer des opérations de gestion telles que l'interrogation de la base de données ou même sa suppression complète. Alors que le point de terminaison /data/remove est correctement protégé par l'annotation @Secured, le point de terminaison /derby n'est pas protégé et est ouvertement accessible aux utilisateurs non authentifiés. Ces points de terminaison ne sont valables que lors de l'utilisation du stockage intégré (derby DB), ce problème ne devrait donc pas affecter les installations utilisant un stockage externe (e.g. mysql)
- CVE-2021-29441Élevée8.6
Nacos est une plateforme conçue pour la découverte dynamique de services ainsi que pour la configuration et la gestion des services. Dans Nacos avant la version 1.4.1, lorsqu'il est configuré pour utiliser l'authentification (-Dnacos.core.auth.enabled=true), Nacos utilise le filtre servlet AuthFilter pour imposer l'authentification. Ce filtre contient une backdoor qui permet aux serveurs Nacos de contourner ce filtre et donc d'ignorer les contrôles d'authentification. Ce mécanisme repose sur l'en-tête HTTP user-agent et peut donc être facilement usurpé. Ce problème peut permettre à tout utilisateur d'effectuer toute tâche administrative sur le serveur Nacos.
- CVE-2021-21224Élevée8.8
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- CVE-2021-21220Élevée8.8
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-21206Élevée8.8
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-22205Critique10.0
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
- CVE-2021-22204Moyenne6.8
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
This product uses the NVD API but is not endorsed or certified by the NVD.