8.5
CVE-2021-47829 - DHCP Broadband 4.1.0.1503 - 'dhcpt.exe' Unquoted Service Path
DHCP Broadband 4.1.0.1503 contains an unquoted service path vulnerability in its service configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path in 'C:\Program Files\DHCP Broadband 4\dhcpt.exe' to inject malicious code that will exβ¦
8.5
CVE-2021-47828 - BOOTP Turbo 2.0.0.1253 - 'bootpt.exe' Unquoted Service Path
BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to execute arbitrary code with elevated LocalSystem privileges during system startup or reboot.
4.6
CVE-2021-47827 - WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service
WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash the application by pasting malformed input. Attackers can trigger the vulnerability by copying a 300-character buffer of repeated 'A' characters into the mashREPL input field, causβ¦
8.5
CVE-2021-47826 - Acer Backup Manager Module 3.0.0.99 - 'IScheduleSvc.exe' Unquoted Service Path
Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables thatβ¦
8.5
CVE-2021-47825 - Acer Updater Service 1.2.3500.0 - 'UpdaterService.exe' Unquoted Service Path
Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permβ¦
4.6
CVE-2021-47824 - iDailyDiary 4.30 - Denial of Service (PoC)
iDailyDiary 4.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the preferences tab name field. Attackers can paste a 2,000,000 character buffer into the default diary tab name to trigger an application crash.
8.5
CVE-2021-47823 - ePowerSvc 6.0.3008.0 - 'ePowerSvc.exe' Unquoted Service Path
Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissionβ¦
8.5
CVE-2021-47822 - DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path
DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path locations to gain system-level aβ¦
4.6
CVE-2021-47821 - RarmaRadio 2.72.8 - Denial of Service
RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing network configuration fields with large character buffers. Attackers can generate a 100,000 character buffer and paste it into multiple network settings fields to trigger appliβ¦
5.1
CVE-2021-47820 - Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF)
Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.