Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2021-03-22 CVE-2021-26578 SQL Injection vulnerability in HPE Network Orchestrator
A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5.
network
low complexity
hpe CWE-89
5.0
2021-03-22 CVE-2021-25265 Unspecified vulnerability in Sophos Connect
A malicious website could execute code remotely in Sophos Connect Client before version 2.1.
network
sophos
6.8
2021-03-22 CVE-2021-22309 Use of Insufficiently Random Values vulnerability in Huawei products
There is insecure algorithm vulnerability in Huawei products.
network
low complexity
huawei CWE-330
5.0
2021-03-22 CVE-2020-9213 Unspecified vulnerability in Huawei products
There is a denial of service vulnerability in some huawei products.
network
low complexity
huawei
5.0
2021-03-22 CVE-2020-9212 Unspecified vulnerability in Huawei Usg9500 Firmware
There is a vulnerability in some version of USG9500 that the device improperly handles the information when a user logs in to device.
network
low complexity
huawei
4.0
2021-03-22 CVE-2020-9206 Unspecified vulnerability in Huawei Eudc660 Firmware V100R005C00
The eUDC660 product has a resource management vulnerability.
local
low complexity
huawei
4.6
2021-03-22 CVE-2021-28972 Classic Buffer Overflow vulnerability in multiple products
In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly.
local
low complexity
linux fedoraproject netapp CWE-120
6.7
2021-03-22 CVE-2021-28971 Improper Handling of Exceptional Conditions vulnerability in multiple products
In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.
local
low complexity
linux fedoraproject debian netapp CWE-755
5.5
2021-03-22 CVE-2021-27596 Unspecified vulnerability in SAP 3D Visual Enterprise Viewer 9
When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
network
sap
4.3
2021-03-22 CVE-2021-27595 Unspecified vulnerability in SAP 3D Visual Enterprise Viewer 9
When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
network
sap
4.3