2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1982 | HIGH | 7.5 | 0.6% | Nov 12, 2021 | Possible denial of service scenario due to improper input validation of received NAS OTA message in Snapdragon Auto, Sna... |
| CVE-2021-1981 | CRITICAL | 9.1 | 0.6% | Nov 12, 2021 | Possible buffer over read due to improper IE size check of Bearer capability IE in MT setup request from network in Snap... |
| CVE-2021-1979 | HIGH | 7.8 | 0.2% | Nov 12, 2021 | Possible buffer overflow due to improper validation of FTM command payload in Snapdragon Auto, Snapdragon Compute, Snapd... |
| CVE-2021-1975 | CRITICAL | 9.8 | 0.8% | Nov 12, 2021 | Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdra... |
| CVE-2021-1973 | HIGH | 7.8 | 0.1% | Nov 12, 2021 | A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon C... |
| CVE-2021-1924 | MEDIUM | 5.5 | 0.2% | Nov 12, 2021 | Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, ... |
| CVE-2021-1921 | HIGH | 7 | 0.1% | Nov 12, 2021 | Possible memory corruption due to Improper handling of hypervisor unmap operations for concurrent memory operations in S... |
| CVE-2021-1912 | HIGH | 7.8 | 0.1% | Nov 12, 2021 | Possible integer overflow can occur due to improper length check while calculating count and grace period in Snapdragon ... |
| CVE-2021-1903 | MEDIUM | 5.3 | 0.5% | Nov 12, 2021 | Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or... |
| CVE-2021-42775 | CRITICAL | 9.1 | 1.0% | Nov 12, 2021 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly... |
| CVE-2021-42774 | CRITICAL | 9.8 | 2.4% | Nov 12, 2021 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly... |
| CVE-2021-42773 | HIGH | 7.5 | 1.0% | Nov 12, 2021 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly... |
| CVE-2021-37910 | MEDIUM | 5.3 | 2.4% | Nov 12, 2021 | ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerabi... |
| CVE-2021-34422 | CRITICAL | 9 | 1.3% | Nov 11, 2021 | The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a ... |
| CVE-2021-34421 | MEDIUM | 4.3 | 0.7% | Nov 11, 2021 | The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properl... |
| CVE-2021-34420 | HIGH | 7.4 | 0.4% | Nov 11, 2021 | The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files ... |
| CVE-2021-34419 | MEDIUM | 5.3 | 0.6% | Nov 11, 2021 | In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a re... |
| CVE-2021-34418 | MEDIUM | 5.3 | 0.6% | Nov 11, 2021 | The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-P... |
| CVE-2021-34417 | HIGH | 7.2 | 1.2% | Nov 11, 2021 | The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.202... |
| CVE-2021-3912 | MEDIUM | 6.5 | 0.8% | Nov 11, 2021 | OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory... |
| CVE-2021-3911 | MEDIUM | 6.5 | 0.9% | Nov 11, 2021 | If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash. |
| CVE-2021-3910 | HIGH | 7.5 | 1.3% | Nov 11, 2021 | OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character). |
| CVE-2021-3909 | HIGH | 7.5 | 1.5% | Nov 11, 2021 | OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRP... |
| CVE-2021-3908 | HIGH | 7.5 | 0.7% | Nov 11, 2021 | OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, the... |
| CVE-2021-3907 | CRITICAL | 9.8 | 4.1% | Nov 11, 2021 | OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now