VYPR

CVEs

101,972 total · page 1257 of 2,040

  • CVE-2021-31383HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    In Point to MultiPoint (P2MP) scenarios within established sessions between network or adjacent neighbors the improper use of a source to destination copy write operation combined with a Stack-based Buffer Overflow on certain specific packets processed by the routing protocol…

  • CVE-2021-31379HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device which is disabled as a result of the…

  • CVE-2021-31376HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending specific DHCPv6 packets to the device and crashing the FXPC service. Continued receipt and…

  • CVE-2021-31375HigOct 19, 2021
    risk 0.47cvss 7.2epss 0.01

    An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BGP update which may cause RPKI…

  • CVE-2021-31374HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    On Juniper Networks Junos OS and Junos OS Evolved devices processing a specially crafted BGP UPDATE or KEEPALIVE message can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued receipt and processing of this message will create…

  • CVE-2021-31373HigOct 19, 2021
    risk 0.52cvss 8.0epss 0.01

    A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may allow a remote authenticated user to inject persistent and malicious scripts. An attacker can exploit this vulnerability to steal sensitive data and credentials…

  • CVE-2021-31372HigOct 19, 2021
    risk 0.57cvss 8.8epss 0.01

    An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated J-Web attacker to escalate their privileges to root over the target device. This issue affects: Juniper Networks Junos OS All versions prior to 18.3R3-S5; 18.4…

  • CVE-2021-31368HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band management ethernet port.…

  • CVE-2021-31360HigOct 19, 2021
    risk 0.46cvss 7.1epss 0.00

    An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending…

  • CVE-2021-31359HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to cause the Juniper DHCP daemon (jdhcpd) process to crash, resulting in a Denial of Service (DoS), or execute arbitrary commands as root. Continued…

  • CVE-2021-31358HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A command injection vulnerability in sftp command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The…

  • CVE-2021-31357HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user.…

  • CVE-2021-31356HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The…

  • CVE-2021-31355HigOct 19, 2021
    risk 0.52cvss 8.0epss 0.01

    A persistent cross-site scripting (XSS) vulnerability in the captive portal graphical user interface of Juniper Networks Junos OS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session,…

  • CVE-2021-31354HigOct 19, 2021
    risk 0.46cvss 7.1epss 0.01

    An Out Of Bounds (OOB) access vulnerability in the handling of responses by a Juniper Agile License (JAL) Client in Juniper Networks Junos OS and Junos OS Evolved, configured in Network Mode (to use Juniper Agile License Manager) may allow an attacker to cause a partial Denial…

  • CVE-2021-31353HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an attacker to inject a specific BGP update, causing the routing protocol daemon (RPD) to crash and restart, leading to a Denial of Service (DoS). Continued…

  • CVE-2021-31351HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An Improper Check for Unusual or Exceptional Conditions in packet processing on the MS-MPC/MS-MIC utilized by Juniper Networks Junos OS allows a malicious attacker to send a specific packet, triggering the MS-MPC/MS-MIC to reset, causing a Denial of Service (DoS). Continued…

  • CVE-2021-31350HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root, leading to…

  • CVE-2021-0299HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An Improper Handling of Exceptional Conditions vulnerability in the processing of a transit or directly received malformed IPv6 packet in Juniper Networks Junos OS results in a kernel crash, causing the device to restart, leading to a Denial of Service (DoS). Continued receipt…

  • CVE-2021-0296HigOct 19, 2021
    risk 0.48cvss 7.4epss 0.00

    The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header which allows servers to indicate that content from the requested domain will only be served over HTTPS. The lack of HSTS may leave the system…

  • CVE-2021-41149HigOct 19, 2021
    risk 0.46cvss 8.2epss 0.01

    Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0, does not properly sanitize target names when caching a repository, or when saving specific targets to an output directory. When…

  • CVE-2021-41131HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.01

    python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path traversal vulnerability that in the worst case can overwrite files ending in `.json` anywhere on the client system on a call to…

  • CVE-2021-32664HigOct 19, 2021
    risk 0.00cvss 8.1epss 0.01

    Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5.

  • CVE-2021-32663HigOct 19, 2021
    risk 0.00cvss 8.7epss 0.01

    iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later

  • CVE-2021-37137HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.06

    The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be…

  • CVE-2021-37136HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.06

    The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

  • CVE-2021-30849HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.02

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code…

  • CVE-2021-30848HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.

  • CVE-2021-30847HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.03

    This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

  • CVE-2021-30846HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30844HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.02

    A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A remote attacker may be able to leak memory.

  • CVE-2021-30843HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

  • CVE-2021-30842HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

  • CVE-2021-30841HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

  • CVE-2021-30838HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to execute arbitrary code with system privileges on devices with an Apple Neural Engine.

  • CVE-2021-30837HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.02

    A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-30835HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.03

    This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.

  • CVE-2021-30832HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.00

    A memory corruption issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local attacker may be able to elevate their privileges.

  • CVE-2021-30830HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A malicious application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-30829HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.00

    A URI parsing issue was addressed with improved parsing. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local user may be able to execute arbitrary files.

  • CVE-2021-30827HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.00

    A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local attacker may be able to elevate their privileges.

  • CVE-2021-30826HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. In certain situations, the baseband would fail to enable integrity and ciphering protection.

  • CVE-2021-30825HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15. A local attacker may be able to cause unexpected application termination or arbitrary code execution.

  • CVE-2021-30807HigKEVOct 19, 2021
    risk 0.65cvss 7.8epss 0.29

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this…

  • CVE-2021-30358HigOct 19, 2021
    risk 0.49cvss 7.2epss 0.27

    Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent.

  • CVE-2020-29622HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-005 Catalina. Mounting a maliciously crafted NFS network share may lead to arbitrary code execution with system privileges.

  • CVE-2021-3889HigOct 19, 2021
    risk 0.00cvss 8.1epss 0.01

    libmobi is vulnerable to Use of Out-of-range Pointer Offset

  • CVE-2021-3888HigOct 19, 2021
    risk 0.00cvss 8.1epss 0.01

    libmobi is vulnerable to Use of Out-of-range Pointer Offset

  • CVE-2021-3872HigOct 19, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2021-3869HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.01

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference