Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-24 | CVE-2021-29955 | Injection vulnerability in Mozilla Firefox A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. | 5.3 |
2021-06-23 | CVE-2021-29084 | Injection vulnerability in Synology products Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors. | 7.5 |
2021-06-23 | CVE-2021-29085 | Injection vulnerability in Synology products Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors. | 7.5 |
2021-06-22 | CVE-2021-0551 | Injection vulnerability in Google Android 11.0 In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. | 6.5 |
2021-06-22 | CVE-2021-0553 | Injection vulnerability in Google Android 11.0 In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. | 7.3 |
2021-06-22 | CVE-2021-0567 | Injection vulnerability in Google Android 11.0 In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. | 7.8 |
2021-06-22 | CVE-2021-20736 | Injection vulnerability in Weseek Growi NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors. | 9.1 |
2021-06-21 | CVE-2018-25016 | Injection vulnerability in Greenbone OS and Greenbone Security Assistant Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection. | 9.8 |
2021-06-16 | CVE-2021-29702 | Injection vulnerability in IBM DB2 Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. | 7.5 |
2021-06-16 | CVE-2021-28979 | Injection vulnerability in Thalesgroup Safenet Keysecure 8.12.0 SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. | 6.5 |