CVE-2021-1367

CVSS v3 Score
4.3
Medium
CVSS v2 Score
2.9
Low

Vulnerability Description

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted PIM packet to an affected device. A successful exploit could allow the attacker to cause a traffic loop, resulting in a DoS condition.

CVSS:4.3(Medium)

The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than...

CWE-202013
CVSS:4.3(Medium)

An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

CWE-202013
CVSS:4.3(Medium)

MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.

CWE-202013
CVSS:4.3(Medium)

ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspecified vectors.

CWE-202015
CVSS:4.3(Medium)

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability."

CWE-202016
CVSS:4.3(Medium)

IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA messa...

CWE-202016