Search Results (35211 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-38651 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2024-11-21 7.6 High
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-38650 1 Microsoft 2 365 Apps, Office 2024-11-21 7.6 High
Microsoft Office Spoofing Vulnerability
CVE-2021-38644 1 Microsoft 1 Mpeg-2 Video Extension 2024-11-21 7.8 High
Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability
CVE-2021-38642 2 Apple, Microsoft 3 Iphone Os, Edge, Edge Chromium 2024-11-21 6.1 Medium
Microsoft Edge for iOS Spoofing Vulnerability
CVE-2021-38641 2 Google, Microsoft 3 Android, Edge, Edge Chromium 2024-11-21 6.1 Medium
Microsoft Edge for Android Spoofing Vulnerability
CVE-2021-38637 1 Microsoft 10 Windows 10, Windows 10 1809, Windows 10 1909 and 7 more 2024-11-21 5.5 Medium
Windows Storage Information Disclosure Vulnerability
CVE-2021-38636 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 5.5 Medium
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-38635 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 5.5 Medium
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-38632 1 Microsoft 11 Windows 10, Windows 10 1607, Windows 10 1809 and 8 more 2024-11-21 5.7 Medium
BitLocker Security Feature Bypass Vulnerability
CVE-2021-38631 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2024-11-21 4.4 Medium
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2021-38629 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2024-11-21 6.5 Medium
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
CVE-2021-38591 1 Google 1 Android 2024-11-21 3.3 Low
An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt6883. Attackers can change some of the NvRAM content by leveraging the misconfiguration of a debug command. The LG ID is LVE-SMP-210005 (August 2021).
CVE-2021-38589 1 Cpanel 1 Cpanel 2024-11-21 8.1 High
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
CVE-2021-38586 1 Cpanel 1 Cpanel 2024-11-21 4.4 Medium
In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).
CVE-2021-38573 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2024-11-21 9.8 Critical
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.
CVE-2021-38572 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2024-11-21 9.8 Critical
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.
CVE-2021-38565 1 Foxitsoftware 2 Pdf Editor, Pdf Reader 2024-11-21 7.5 High
An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows writing to arbitrary files via submitForm.
CVE-2021-38549 1 Benda 2 Miracase Hmub500, Miracase Hmub500 Firmware 2024-11-21 5.9 Medium
MIRACASE MHUB500 USB splitters through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the USB splitter supplies power to some speakers. The power indicator LED of the USB splitter is connected directly to the power line, as a result, the intensity of the USB splitter's power indicator LED is correlative to its power consumption. The sound played by the connected speakers affects the USB splitter's power consumption and as a result is also correlative to the light intensity of the LED. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LED of the USB splitter, we can recover the sound played by the connected speakers.
CVE-2021-38548 1 Jbl 2 Go 2, Go 2 Firmware 2024-11-21 5.9 Medium
JBL Go 2 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.
CVE-2021-38547 1 Logitech 4 S120, S120 Firmware, Z120 and 1 more 2024-11-21 5.9 Medium
Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.