2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-1982HIGH7.5Possible denial of service scenario due to improper input validation of received NAS OTA message in Snapdragon Auto, Sna...
CVE-2021-1981CRITICAL9.1Possible buffer over read due to improper IE size check of Bearer capability IE in MT setup request from network in Snap...
CVE-2021-1979HIGH7.8Possible buffer overflow due to improper validation of FTM command payload in Snapdragon Auto, Snapdragon Compute, Snapd...
CVE-2021-1975CRITICAL9.8Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdra...
CVE-2021-1973HIGH7.8A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon C...
CVE-2021-1924MEDIUM5.5Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, ...
CVE-2021-1921HIGH7Possible memory corruption due to Improper handling of hypervisor unmap operations for concurrent memory operations in S...
CVE-2021-1912HIGH7.8Possible integer overflow can occur due to improper length check while calculating count and grace period in Snapdragon ...
CVE-2021-1903MEDIUM5.3Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or...
CVE-2021-42775CRITICAL9.1Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly...
CVE-2021-42774CRITICAL9.8Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly...
CVE-2021-42773HIGH7.5Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly...
CVE-2021-37910MEDIUM5.3ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerabi...
CVE-2021-34422CRITICAL9The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a ...
CVE-2021-34421MEDIUM4.3The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properl...
CVE-2021-34420HIGH7.4The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files ...
CVE-2021-34419MEDIUM5.3In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a re...
CVE-2021-34418MEDIUM5.3The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-P...
CVE-2021-34417HIGH7.2The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.202...
CVE-2021-3912MEDIUM6.5OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory...
CVE-2021-3911MEDIUM6.5If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash.
CVE-2021-3910HIGH7.5OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
CVE-2021-3909HIGH7.5OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRP...
CVE-2021-3908HIGH7.5OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, the...
CVE-2021-3907CRITICAL9.8OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now