Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Versiondog CRITICAL 9.8
CVE-2021-38481

The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of the supplied JOB ID provided …

Fix: after 8.0.0
Fix from $2,300 2021-10-22
Versiondog CRITICAL 9.8
CVE-2021-38449

Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these parameters, an attacker could rewrit…

Fix: after 8.0.0
Fix from $2,300 2021-10-22
Versiondog CRITICAL 9.8
CVE-2021-38457

The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing …

Fix: 8.0.0+
Fix from $2,300 2021-10-22
Versiondog CRITICAL 9.8
CVE-2021-38459

The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often…

Fix: 8.0.0+
Fix from $2,300 2021-10-22
Versiondog CRITICAL 9.8
CVE-2021-38477

There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and…

Fix: 8.0.0+
Fix from $2,300 2021-10-22
Versiondog CRITICAL 9.1
CVE-2021-38453

Some API functions allow interaction with the registry, which includes reading values as well as data modification.

Fix: 8.0.0+
Fix from $2,300 2021-10-22
Versiondog CRITICAL 9.1
CVE-2021-38471

There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.

Fix: 8.0.0+
Fix from $2,300 2021-10-22
Versiondog HIGH 8.8
CVE-2021-38473

The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack overflow.

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Versiondog HIGH 8.8
CVE-2021-38475

The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Versiondog HIGH 8.2
CVE-2021-38461

The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Versiondog HIGH 8.1
CVE-2021-38463

The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functio…

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Versiondog HIGH 8.1
CVE-2021-38467

A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then control what memory regions will…

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Versiondog HIGH 7.5
CVE-2021-38479

Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory regions. An attacker can manipu…

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Versiondog HIGH 7.1
CVE-2021-38469

Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled s…

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Versiondog MEDIUM 6.5
CVE-2021-38455

The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls wit…

Fix: 8.0.0+
Fix from $1,600 2021-10-22
Versiondog MEDIUM 6.5
CVE-2021-38465

The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by gene…

Fix: 8.0.0+
Fix from $1,600 2021-10-22
Versiondog MEDIUM 5.7
CVE-2021-38451

The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes, the user must supp…

Fix: 8.0.0+
Fix from $1,600 2021-10-22