Publication Date: |
2022-03-08 |
Last Update: |
2022-03-08 |
Current Version: |
V1.0 |
CVSS v3.1 Base Score: |
9.8 |
CVSS v3.1 Base Score |
5.9 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-476: NULL Pointer Dereference |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-20: Improper Input Validation |
CVSS v3.1 Base Score |
9.8 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-681: Incorrect Conversion between Numeric Types |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-20: Improper Input Validation |
CVSS v3.1 Base Score |
5.5 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-674: Uncontrolled Recursion |
CVSS v3.1 Base Score |
9.8 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-754: Improper Check for Unusual or Exceptional Conditions |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-476: NULL Pointer Dereference |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-476: NULL Pointer Dereference |
CVSS v3.1 Base Score |
5.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-755: Improper Handling of Exceptional Conditions |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-434: Unrestricted Upload of File with Dangerous Type |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-476: NULL Pointer Dereference |
CVSS v3.1 Base Score |
5.9 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-476: NULL Pointer Dereference |
CVSS v3.1 Base Score |
7.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C |
CWE: |
CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C |
CWE: |
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
CVSS v3.1 Base Score |
7.1 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (‘Injection’) |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-416: Use After Free |
CVSS v3.1 Base Score |
8.1 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-416: Use After Free |
CVSS v3.1 Base Score |
3.7 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C |
CWE: |
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-674: Uncontrolled Recursion |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C |
CWE: |
CWE-295: Improper Certificate Validation |
CVSS v3.1 Base Score |
6.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-444: Inconsistent Interpretation of HTTP Requests (‘HTTP Request Smuggling’) |
CVSS v3.1 Base Score |
8.1 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-476: NULL Pointer Dereference |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-665: Improper Initialization |
CVSS v3.1 Base Score |
9.8 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-416: Use After Free |
CVSS v3.1 Base Score |
7.0 |
CVSS Vector |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-416: Use After Free |
CVSS v3.1 Base Score |
5.5 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-20: Improper Input Validation |
CVSS v3.1 Base Score |
5.5 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-476: NULL Pointer Dereference |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-416: Use After Free |
CVSS v3.1 Base Score |
5.5 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-787: Out-of-bounds Write |
CVSS v3.1 Base Score |
9.8 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) |
CVSS v3.1 Base Score |
5.9 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-476: NULL Pointer Dereference |
CVSS v3.1 Base Score |
7.4 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-295: Improper Certificate Validation |
CVSS v3.1 Base Score |
5.6 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C |
CWE: |
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) |
CVSS v3.1 Base Score |
9.8 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) |
CVSS v3.1 Base Score |
7.4 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-125: Out-of-bounds Read |
CVSS v3.1 Base Score |
5.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-400: Uncontrolled Resource Consumption |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-20: Improper Input Validation |
CVSS v3.1 Base Score |
3.7 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-290: Authentication Bypass by Spoofing |
CVSS v3.1 Base Score |
5.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-668: Exposure of Resource to Wrong Sphere |
CVSS v3.1 Base Score |
3.1 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-909: Missing Initialization of Resource |
CVSS v3.1 Base Score |
8.1 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-416: Use After Free |
CVSS v3.1 Base Score |
5.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-125: Out-of-bounds Read |
CVSS v3.1 Base Score |
7.8 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-732: Incorrect Permission Assignment for Critical Resource |
CVSS v3.1 Base Score |
6.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-354: Improper Validation of Integrity Check Value |
CVSS v3.1 Base Score |
5.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-522: Insufficiently Protected Credentials |
CVSS v3.1 Base Score |
3.7 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-706: Use of Incorrectly-Resolved Name or Reference |
CVSS v3.1 Base Score |
5.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-908: Use of Uninitialized Resource |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-295: Improper Certificate Validation |
CVSS v3.1 Base Score |
9.8 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-416: Use After Free |
CVSS v3.1 Base Score |
9.8 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-20: Improper Input Validation |
CVSS v3.1 Base Score |
5.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-295: Improper Certificate Validation |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-416: Use After Free |
CVSS v3.1 Base Score |
9.1 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-415: Double Free |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-319: Cleartext Transmission of Sensitive Information |
CVSS v3.1 Base Score |
5.9 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-345: Insufficient Verification of Data Authenticity |
CVSS v3.1 Base Score |
5.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C |
CWE: |
CWE-20: Improper Input Validation |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-190: Integer Overflow or Wraparound |
CVSS v3.1 Base Score |
6.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-617: Reachable Assertion |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-617: Reachable Assertion |
CVSS v3.1 Base Score |
9.8 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-617: Reachable Assertion |
CVSS v3.1 Base Score |
5.3 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C |
CWE: |
CWE-20: Improper Input Validation |
CVSS v3.1 Base Score |
7.5 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-20: Improper Input Validation |
CVSS v3.1 Base Score |
8.1 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) |
CVSS v3.1 Base Score |
8.1 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) |
CVSS v3.1 Base Score |
8.6 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-59: Improper Link Resolution Before File Access (‘Link Following’) |
CVSS v3.1 Base Score |
8.6 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-59: Improper Link Resolution Before File Access (‘Link Following’) |
CVSS v3.1 Base Score |
8.6 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) |
CVSS v3.1 Base Score |
7.8 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-61: UNIX Symbolic Link (Symlink) Following |
CVSS v3.1 Base Score |
7.8 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-61: UNIX Symbolic Link (Symlink) Following |