CVE-2021-36946
published 2021-08-12CVE-2021-36946: Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
PriorityP422medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.95%
57.1th percentile
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 4.15.0-193.204 | 4.15.0-193.204 |
| microsoft | dynamics_365_business_central | — | — |
| microsoft | dynamics_365_business_central | — | — |
| microsoft | dynamics_365_business_central_spring_2019_update | >= 14.0.0 < Application Build 14.27.47563, Platform Build 14.0 | Application Build 14.27.47563, Platform Build 14.0 |
| microsoft | dynamics_nav | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | microsoft_dynamics_365_business_central_2020_release_wave_1_update_16.15 | >= 16.0 < Application Build 16.15.28500, Platform Build 16.0 | Application Build 16.15.28500, Platform Build 16.0 |
| microsoft | microsoft_dynamics_365_business_central_2020_release_wave_2_update_17.9 | >= 17.0 < Application Build 17.9.28504, Platform Build 17.0. | Application Build 17.9.28504, Platform Build 17.0. |
| microsoft | microsoft_dynamics_nav_2017 | >= 1.0 < 30601 | 30601 |
| microsoft | microsoft_dynamics_nav_2018 | >= 1.0 < 47562 | 47562 |
| msrc | dynamics_365_business_central_2019_spring_update | — | — |
| msrc | microsoft_dynamics_365_business_central_2020_release_wave_1_update_16.15 | — | — |
| msrc | microsoft_dynamics_365_business_central_2020_release_wave_2_update_17.9 | — | — |
| msrc | microsoft_dynamics_nav_2017 | — | — |
| msrc | microsoft_dynamics_nav_2018 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv6.7MEDIUM
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-azure vulnerabilities
osv·2022-10-03·CVSS 6.7
CVE-2021-33655 linux-azure vulnerabilities
linux-azure vulnerabilities
It was discovered that the framebuffer driver on the Linux kernel did not
verify size limits when changing font or screen size, leading to an out-of-
bounds write. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2021-33655)
Domingo Dirutigliano and Nicola Guerrera discovered that the netfilter
subsystem in the Linux kernel did not properly handle rules that truncated
packets below the packet header size. When such rules are in place, a
remote attacker could possibly use this to cause a denial of service
(system crash). (CVE-2022-36946)
OSV
linux, linux-aws, linux-aws-hwe, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, lnux-hwe, inux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2022-09-21·CVSS 6.7
CVE-2021-33655 linux, linux-aws, linux-aws-hwe, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, lnux-hwe, inux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, lnux-hwe, inux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the framebuffer driver on the Linux kernel did not
verify size limits when changing font or screen size, leading to an out-of-
bounds write. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2021-33655)
Domingo Dirutigliano and Nicola Guerrera discovered that the netfilter
subsystem in the Linux kernel did not properly handle rules that truncated
packets below the packet header size. When such rules are in place, a
remote attacker could possibly use this to cause a denial of service
(system crash). (CVE-2022-36946)
GHSA
GHSA-2fq7-f2fp-mgxx: Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-36946 [MEDIUM] CWE-79 GHSA-2fq7-f2fp-mgxx: Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Microsoft
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
vendor_msrc·2021-08-10·CVSS 5.4
CVE-2021-36946 [MEDIUM] Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Microsoft Dynamics: Microsoft Dynamics
Microsoft: Microsoft
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=103354
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=103357
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=103358
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=103356
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=103355
No detection rules found.
No public exploits indexed.
2021-08-12
Published