Vulnerabilities > Dell > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-24 CVE-2021-21572 Out-of-bounds Write vulnerability in Dell products
Dell BIOSConnect feature contains a buffer overflow vulnerability.
local
high complexity
dell CWE-787
7.5
2021-06-24 CVE-2021-21573 Out-of-bounds Write vulnerability in Dell products
Dell BIOSConnect feature contains a buffer overflow vulnerability.
local
high complexity
dell CWE-787
7.5
2021-06-24 CVE-2021-21574 Out-of-bounds Write vulnerability in Dell products
Dell BIOSConnect feature contains a buffer overflow vulnerability.
local
high complexity
dell CWE-787
7.5
2021-05-21 CVE-2021-21549 Cross-Site Request Forgery (CSRF) vulnerability in Dell Xtremio Management Server 6.3.0
Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS.
network
low complexity
dell CWE-352
8.8
2021-05-04 CVE-2021-21551 Unspecified vulnerability in Dell Dbutil 2 3.Sys
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure.
local
low complexity
dell
7.8
2021-04-30 CVE-2021-21540 Out-of-bounds Write vulnerability in Dell Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a stack-based overflow vulnerability.
network
low complexity
dell CWE-787
8.1
2021-04-30 CVE-2021-21539 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Dell Idrac9 Firmware
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability.
network
high complexity
dell CWE-367
7.1
2021-04-30 CVE-2021-21530 OS Command Injection vulnerability in Dell Openmanage Enterprise-Modular
Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability.
network
low complexity
dell CWE-78
8.8
2021-04-30 CVE-2021-21531 Incorrect Resource Transfer Between Spheres vulnerability in Dell products
Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability.
local
low complexity
dell CWE-669
7.8
2021-04-30 CVE-2021-21535 Missing Authentication for Critical Function vulnerability in Dell Hybrid Client 1.0/1.1/1.1.01
Dell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability.
local
low complexity
dell CWE-306
7.8