Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In June 2021
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
CVSS Score
5.5
EPSS Score
0.001
Published
2021-06-08
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.
CVSS Score
5.5
EPSS Score
0.005
Published
2021-06-08
Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-06-08
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
CVSS Score
7.5
EPSS Score
0.004
Published
2021-06-08
The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir function.
CVSS Score
5.3
EPSS Score
0.004
Published
2021-06-08
If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without proper authentication. Roon Labs has already fixed this vulnerability in the following versions: Roon Server 2021-05-18 and later
CVSS Score
7.5
EPSS Score
0.003
Published
2021-06-08
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has already fixed this vulnerability in the following versions: Roon Server 2021-05-18 and later
CVSS Score
7.2
EPSS Score
0.036
Published
2021-06-08
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
CVSS Score
6.1
EPSS Score
0.006
Published
2021-06-07
The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
CVSS Score
6.1
EPSS Score
0.007
Published
2021-06-07
EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version 8.13.6, and from 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.
CVSS Score
6.1
EPSS Score
0.006
Published
2021-06-07


Contact Us

Shodan ® - All rights reserved