Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In December 2021
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
CVSS Score
8.8
EPSS Score
0.039
Published
2021-12-07
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.
CVSS Score
9.8
EPSS Score
0.658
Published
2021-12-07
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
CVSS Score
9.8
EPSS Score
0.045
Published
2021-12-07
A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
CVSS Score
8.8
EPSS Score
0.773
Published
2021-12-07
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
CVSS Score
8.8
EPSS Score
0.622
Published
2021-12-07
A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
CVSS Score
8.8
EPSS Score
0.665
Published
2021-12-07
A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
CVSS Score
8.8
EPSS Score
0.701
Published
2021-12-07
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.
CVSS Score
8.1
EPSS Score
0.028
Published
2021-12-07
Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious RGB file.
CVSS Score
3.3
EPSS Score
0.018
Published
2021-12-07
Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious SGI file.
CVSS Score
3.3
EPSS Score
0.021
Published
2021-12-07


Contact Us

Shodan ® - All rights reserved