From DHS/US-CERT’s Nationwide Vulnerability Database
CVE-2021-20588
PUBLISHED: 2021-02-19
Improper dealing with of size parameter inconsistency vulnerability in Mitsubishi Electrical FA Engineering Software program(C Controller module setting and monitoring software all variations, CPU Module Logging Configuration Instrument all variations, CW Configurator all variations, Knowledge Switch all variations, EZSocket all ve…
CVE-2021-26713
PUBLISHED: 2021-02-19
A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk earlier than 16.16.1, 17.x earlier than 17.9.2, and 18.x earlier than 18.2.1 and Licensed Asterisk earlier than 16.8-cert6 permits an authenticated WebRTC shopper to trigger an Asterisk crash by sending a number of maintain/unhold requests in fast succession. T…
CVE-2020-35499
PUBLISHED: 2021-02-19
A NULL pointer dereference flaw in kernel variations prior to five.11 could also be seen if sco_sock_getsockopt operate in internet/bluetooth/sco.c shouldn’t have a sanity verify for a socket connection, when utilizing BT_SNDMTU/BT_RCVMTU for SCO sockets. This might enable an area attacker with a particular person privilege to c…
CVE-2021-20587
PUBLISHED: 2021-02-19
Heap-based buffer overflow vulnerability in Mitsubishi Electrical FA Engineering Software program (C Controller module setting and monitoring software all variations, CPU Module Logging Configuration Instrument all variations, CW Configurator all variations, Knowledge Switch all variations, EZSocket all variations, FR Configurator …
CVE-2021-27214
PUBLISHED: 2021-02-19
A Server-side request forgery (SSRF) vulnerability within the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus via 6013 permits a distant unauthenticated attacker to carry out blind HTTP requests or carry out a Cross-site scripting (XSS) assault in opposition to the executive interface through an HTTP…