CVE-2021-33708

CVSS v3 Score
7.6
High
CVSS v2 Score
6.5
Medium

Vulnerability Description

Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privileges.

CVSS:7.6(High)

The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, wh...

CWE-202016
CVSS:7.6(High)

Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V ...

CWE-202017
CVSS:7.6(High)

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows gue...

CWE-202017
CVSS:7.6(High)

A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly vali...

CWE-202017
CVSS:7.6(High)

A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "...

CWE-202017
CVSS:7.6(High)

A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "...

CWE-202017