CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.
An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_next_st and ydb_subscript_prev_st have a use-after-free.
An issue was discovered in the nb-connect crate before 1.0.3 for Rust. It may have invalid memory access for certain versions of the standard library because it relies on a direct cast of std::net::SocketAddrV4 and std::net::SocketAddrV6 data structures.
Traefik before 2.4.5 allows the loading of IFRAME elements from other domains.
VertiGIS WebOffice 10.7 SP1 before patch20210202 and 10.8 SP1 before patch20210207 allows attackers to achieve "Zugriff auf Inhalte der WebOffice Applikation."
Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.
The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.
