We have compiled a list of Security Vulnerabilities that were discovered in November 2021. We are available to assist you if you need help applying or investigating these vulnerabilities.
Google Chrome Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-38004 | 23/11/21 | 4.3 | Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
CVE-2021-38003 | 23/11/21 | 6.8 | Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-38002 | 23/11/21 | 6.8 | Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
CVE-2021-38001 | 23/11/21 | 6.8 | Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37999 | 23/11/21 | 4.3 | Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page. |
CVE-2021-37998 | 23/11/21 | 6.8 | Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37997 | 23/11/21 | 6.8 | Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37996 | 02/11/21 | 4.3 | Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file. |
CVE-2021-37995 | 02/11/21 | 4.3 | Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page. |
CVE-2021-37994 | 02/11/21 | 4.3 | Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
CVE-2021-37993 | 02/11/21 | 6.8 | Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37992 | 02/11/21 | 6.8 | Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37991 | 02/11/21 | 5.1 | Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37990 | 02/11/21 | 4.3 | Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app. |
CVE-2021-37989 | 02/11/21 | 4.3 | Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page. |
CVE-2021-37988 | 02/11/21 | 6.8 | Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who convinced a user to engage in specific gestures to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37987 | 02/11/21 | 6.8 | Use after free in Network APIs in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37986 | 02/11/21 | 6.8 | Heap buffer overflow in Settings in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to engage with Dev Tools to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37985 | 02/11/21 | 6.8 | Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had convinced a user to allow for connection to debugger to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37984 | 02/11/21 | 6.8 | Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37983 | 02/11/21 | 6.8 | Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37982 | 02/11/21 | 6.8 | Use after free in Incognito in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37981 | 02/11/21 | 6.8 | Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
CVE-2021-37979 | 02/11/21 | 6.8 | heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37978 | 02/11/21 | 6.8 | Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-37977 | 02/11/21 | 6.8 | Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2020-6492 | 02/11/21 | 6.8 | Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
CVE-2018-6125 | 02/11/21 | 4.3 | Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page. |
CVE-2018-6122 | 02/11/21 | 6.8 | Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
Firefox Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-38501 | 03/11/21 | 6.8 | Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2. |
CVE-2021-38500 | 03/11/21 | 6.8 | Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93. |
CVE-2021-38499 | 03/11/21 | 6.8 | Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93. |
CVE-2021-38498 | 03/11/21 | 5 | During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2. |
CVE-2021-38497 | 03/11/21 | 4.3 | Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2. |
CVE-2021-38496 | 03/11/21 | 6.8 | During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93. |
CVE-2021-38494 | 03/11/21 | 6.8 | Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 92. |
CVE-2021-38493 | 03/11/21 | 6.8 | Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92. |
CVE-2021-38491 | 03/11/21 | 4.3 | Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox < 92. |
CVE-2021-29993 | 03/11/21 | 5.8 | Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92. |
CVE-2021-29991 | 03/11/21 | 5.8 | Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1. |
RedHat Enterprise Linux Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-3935 | 22/11/21 | 5.1 | When PgBouncer is configured to use “cert” authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1. |
CVE-2021-3672 | 23/11/21 | 7.5 | A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability. |
Windows 10 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-42286 | 10/11/21 | 4.6 | Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability |
CVE-2021-42285 | 10/11/21 | 7.2 | Windows Kernel Elevation of Privilege Vulnerability |
CVE-2021-42284 | 10/11/21 | 7.1 | Windows Hyper-V Denial of Service Vulnerability |
CVE-2021-42283 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-41370. |
CVE-2021-42280 | 10/11/21 | 4.6 | Windows Feedback Hub Elevation of Privilege Vulnerability |
CVE-2021-42279 | 10/11/21 | 5.1 | Chakra Scripting Engine Memory Corruption Vulnerability |
CVE-2021-42277 | 10/11/21 | 4.6 | Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability |
CVE-2021-42276 | 10/11/21 | 6.8 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
CVE-2021-42275 | 10/11/21 | 6.5 | Microsoft COM for Windows Remote Code Execution Vulnerability |
CVE-2021-41379 | 10/11/21 | 4.6 | Windows Installer Elevation of Privilege Vulnerability |
CVE-2021-41378 | 10/11/21 | 6.5 | Windows NTFS Remote Code Execution Vulnerability |
CVE-2021-41377 | 10/11/21 | 4.6 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability |
CVE-2021-41370 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-42283. |
CVE-2021-41367 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41370, CVE-2021-42283. |
CVE-2021-41366 | 10/11/21 | 4.6 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
CVE-2021-41356 | 10/11/21 | 5 | Windows Denial of Service Vulnerability |
CVE-2021-38666 | 10/11/21 | 6.8 | Remote Desktop Client Remote Code Execution Vulnerability |
CVE-2021-38665 | 10/11/21 | 4.3 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
CVE-2021-36957 | 10/11/21 | 4.6 | Windows Desktop Bridge Elevation of Privilege Vulnerability |
CVE-2021-26443 | 10/11/21 | 7.7 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability |
Windows Server 2012 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-42291 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42287. |
CVE-2021-42287 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291. |
CVE-2021-42285 | 10/11/21 | 7.2 | Windows Kernel Elevation of Privilege Vulnerability |
CVE-2021-42284 | 10/11/21 | 7.1 | Windows Hyper-V Denial of Service Vulnerability |
CVE-2021-42283 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-41370. |
CVE-2021-42282 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42287, CVE-2021-42291. |
CVE-2021-42278 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291. |
CVE-2021-42275 | 10/11/21 | 6.5 | Microsoft COM for Windows Remote Code Execution Vulnerability |
CVE-2021-41379 | 10/11/21 | 4.6 | Windows Installer Elevation of Privilege Vulnerability |
CVE-2021-41377 | 10/11/21 | 4.6 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability |
CVE-2021-41370 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-42283. |
CVE-2021-41367 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41370, CVE-2021-42283. |
CVE-2021-41366 | 10/11/21 | 4.6 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
CVE-2021-38666 | 10/11/21 | 6.8 | Remote Desktop Client Remote Code Execution Vulnerability |
CVE-2021-38665 | 10/11/21 | 4.3 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
Windows Server 2016 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-42291 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42287. |
CVE-2021-42287 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291. |
CVE-2021-42285 | 10/11/21 | 7.2 | Windows Kernel Elevation of Privilege Vulnerability |
CVE-2021-42284 | 10/11/21 | 7.1 | Windows Hyper-V Denial of Service Vulnerability |
CVE-2021-42283 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-41370. |
CVE-2021-42282 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42287, CVE-2021-42291. |
CVE-2021-42280 | 10/11/21 | 4.6 | Windows Feedback Hub Elevation of Privilege Vulnerability |
CVE-2021-42279 | 10/11/21 | 5.1 | Chakra Scripting Engine Memory Corruption Vulnerability |
CVE-2021-42278 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291. |
CVE-2021-42277 | 10/11/21 | 4.6 | Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability |
CVE-2021-42276 | 10/11/21 | 6.8 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
CVE-2021-42275 | 10/11/21 | 6.5 | Microsoft COM for Windows Remote Code Execution Vulnerability |
CVE-2021-41379 | 10/11/21 | 4.6 | Windows Installer Elevation of Privilege Vulnerability |
CVE-2021-41378 | 10/11/21 | 6.5 | Windows NTFS Remote Code Execution Vulnerability |
CVE-2021-41377 | 10/11/21 | 4.6 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability |
CVE-2021-41370 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-42283. |
CVE-2021-41367 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41370, CVE-2021-42283. |
CVE-2021-41366 | 10/11/21 | 4.6 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
CVE-2021-41356 | 10/11/21 | 5 | Windows Denial of Service Vulnerability |
CVE-2021-38666 | 10/11/21 | 6.8 | Remote Desktop Client Remote Code Execution Vulnerability |
CVE-2021-38665 | 10/11/21 | 4.3 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
CVE-2021-36957 | 10/11/21 | 4.6 | Windows Desktop Bridge Elevation of Privilege Vulnerability |
CVE-2021-26443 | 10/11/21 | 7.7 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability |
Windows Server 2019 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-42291 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42287. |
CVE-2021-42287 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291. |
CVE-2021-42285 | 10/11/21 | 7.2 | Windows Kernel Elevation of Privilege Vulnerability |
CVE-2021-42284 | 10/11/21 | 7.1 | Windows Hyper-V Denial of Service Vulnerability |
CVE-2021-42283 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-41370. |
CVE-2021-42282 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42287, CVE-2021-42291. |
CVE-2021-42280 | 10/11/21 | 4.6 | Windows Feedback Hub Elevation of Privilege Vulnerability |
CVE-2021-42279 | 10/11/21 | 5.1 | Chakra Scripting Engine Memory Corruption Vulnerability |
CVE-2021-42278 | 10/11/21 | 6.5 | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291. |
CVE-2021-42277 | 10/11/21 | 4.6 | Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability |
CVE-2021-42276 | 10/11/21 | 6.8 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
CVE-2021-42275 | 10/11/21 | 6.5 | Microsoft COM for Windows Remote Code Execution Vulnerability |
CVE-2021-41379 | 10/11/21 | 4.6 | Windows Installer Elevation of Privilege Vulnerability |
CVE-2021-41378 | 10/11/21 | 6.5 | Windows NTFS Remote Code Execution Vulnerability |
CVE-2021-41377 | 10/11/21 | 4.6 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability |
CVE-2021-41370 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-42283. |
CVE-2021-41367 | 10/11/21 | 4.6 | NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41370, CVE-2021-42283. |
CVE-2021-41366 | 10/11/21 | 4.6 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
CVE-2021-41356 | 10/11/21 | 5 | Windows Denial of Service Vulnerability |
CVE-2021-38666 | 10/11/21 | 6.8 | Remote Desktop Client Remote Code Execution Vulnerability |
CVE-2021-38665 | 10/11/21 | 4.3 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
CVE-2021-36957 | 10/11/21 | 4.6 | Windows Desktop Bridge Elevation of Privilege Vulnerability |
CVE-2021-26443 | 10/11/21 | 7.7 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability |
VMware vCenter Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-22049 | 24/11/21 | 7.5 | The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service. |
CVE-2021-22048 | 10/11/21 | 6.5 | The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group. |
CVE-2021-21980 | 24/11/21 | 5 | The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information. |