Original release date: March 29, 2021
High Vulnerabilities
Primary Vendor — Product |
Description | Published | CVSS Score | Source & Patch Info |
---|---|---|---|---|
apache — ofbiz | Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz. | 2021-03-22 | 7.5 | CVE-2021-26295 MLIST CONFIRM MLIST MLIST MLIST |
apache — spamassassin | In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places. | 2021-03-25 | 10 | CVE-2020-1946 MISC DEBIAN |
apkleaks_project — apkleaks | APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows remote attackers to execute arbitrary OS commands via package name inside application manifest. An attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified or could cause other unintended behavior through malicious package name. The problem is fixed in version v2.0.6-dev and above. | 2021-03-24 | 10 | CVE-2021-21386 MISC CONFIRM |
eslint-fixer_project — eslint-fixer | ** UNSUPPORTED WHEN ASSIGNED ** The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repository has been intentionally deleted. | 2021-03-19 | 10 | CVE-2021-26275 MISC MISC |
genivia — gsoap | A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability. | 2021-03-25 | 7.5 | CVE-2021-21783 MISC |
git-bug_project — git-bug | git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in certain PATH situations (most often seen on Windows). | 2021-03-22 | 7.5 | CVE-2021-28955 MISC |
gnu — libmicrohttpd | A flaw was found in libmicrohttpd in versions before 0.9.71. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | 2021-03-25 | 10 | CVE-2021-3466 MISC |
gulpjs — copy-props | The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality. | 2021-03-23 | 7.5 | CVE-2020-28503 CONFIRM CONFIRM CONFIRM |
http-proxy-agent_project — http-proxy-agent | A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter. | 2021-03-19 | 9 | CVE-2019-10196 MISC MISC |
invigo — automatic_device_management | The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application. | 2021-03-25 | 9 | CVE-2020-10583 CONFIRM |
invigo — automatic_device_management | A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database. | 2021-03-25 | 7.5 | CVE-2020-10582 CONFIRM |
it-recht-kanzlei — it-recht-kanzlei | The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection. | 2021-03-19 | 7.5 | CVE-2020-6577 MISC MISC |
linux — linux_kernel | In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name ‘ |