Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-39590 1 Swftools 1 Swftools 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function params_dump() located in abc.c. It allows an attacker to cause Denial of Service.
CVE-2021-39592 1 Swftools 1 Swftools 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_uint() located in pool.c. It allows an attacker to cause Denial of Service.
CVE-2021-32137 1 Gpac 1 Gpac 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
CVE-2021-32134 1 Gpac 1 Gpac 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-32136 1 Gpac 1 Gpac 2021-09-22 6.8 MEDIUM 7.8 HIGH
Heap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
CVE-2021-32135 1 Gpac 1 Gpac 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-39593 1 Swftools 1 Swftools 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_FontExtract_DefineFontInfo() located in swftext.c. It allows an attacker to cause Denial of Service.
CVE-2021-32132 1 Gpac 1 Gpac 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-29643 1 Paessler 1 Prtg Network Monitor 2021-09-22 3.5 LOW 5.4 MEDIUM
PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.
CVE-2021-22526 1 Microfocus 1 Access Manager 2021-09-22 5.8 MEDIUM 6.1 MEDIUM
Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
CVE-2021-39594 1 Swftools 1 Swftools 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
Other An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function updateusage() located in swftext.c. It allows an attacker to cause Denial of Service.
CVE-2021-39595 1 Swftools 1 Swftools 2021-09-22 6.8 MEDIUM 7.8 HIGH
An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function rfx_alloc() located in mem.c. It allows an attacker to cause code Execution.
CVE-2021-39596 1 Swftools 1 Swftools 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_parse() located in code.c. It allows an attacker to cause Denial of Service.
CVE-2021-22524 1 Microfocus 1 Access Manager 2021-09-22 4.0 MEDIUM 4.9 MEDIUM
Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
CVE-2021-39597 1 Swftools 1 Swftools 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_dump2() located in code.c. It allows an attacker to cause Denial of Service.
CVE-2021-39598 1 Swftools 1 Swftools 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function callcode() located in code.c. It allows an attacker to cause Denial of Service.
CVE-2021-22528 1 Microfocus 1 Access Manager 2021-09-22 3.5 LOW 5.4 MEDIUM
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
CVE-2021-25454 1 Google 1 Android 2021-09-22 4.3 MEDIUM 5.5 MEDIUM
OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.
CVE-2021-25457 2 Google, Samsung 4 Android, Exynos 2100, Exynos 980 and 1 more 2021-09-22 2.1 LOW 3.3 LOW
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
CVE-2021-38316 1 Wp Academic People List Project 1 Wp Academic People List 2021-09-22 4.3 MEDIUM 6.1 MEDIUM
The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name parameter in the ~/admin-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.4.1.