Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2021
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
CVSS Score
7.5
EPSS Score
0.002
Published
2021-03-19
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
CVSS Score
7.5
EPSS Score
0.005
Published
2021-03-19
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-03-19
An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.
CVSS Score
7.5
EPSS Score
0.001
Published
2021-03-19
/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.
CVSS Score
7.5
EPSS Score
0.003
Published
2021-03-19
index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability
CVSS Score
6.1
EPSS Score
0.002
Published
2021-03-19
MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work
CVSS Score
8.1
EPSS Score
0.378
Published
2021-03-19
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.
CVSS Score
7.2
EPSS Score
0.489
Published
2021-03-19
TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).
CVSS Score
6.1
EPSS Score
0.002
Published
2021-03-19
Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter.
CVSS Score
5.4
EPSS Score
0.003
Published
2021-03-19


Contact Us

Shodan ® - All rights reserved