CVE-2021-38465
8.0 HIGHThe webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent
Published: 2021-10-22 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 8.0 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-400, CWE-770
Affected products
| Vendor | Product |
|---|---|
| auvesy | versiondog |
Description
The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without limitation in the temp folder of the webinstaller executable.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2021-38481 — The scheduler service running on a specific TCP port enables the user to start and stop jobs (8.1 HIGH)
- CVE-2021-38479 — Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory regions (6.5 MEDIUM)
- CVE-2021-38477 — There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the mani... (9.8 CRITICAL)
- CVE-2021-38475 — The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permi... (7.3 HIGH)
- CVE-2021-38473 — The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack overflow (8.0 HIGH)
Same CWE
- CVE-2026-12325 — Denial-of-service in the Graphics: ImageLib component (6.5 MEDIUM)
- CVE-2026-12319 — Denial-of-service in the Audio/Video: Playback component (6.5 MEDIUM)
- CVE-2026-48854 — Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BE...
- CVE-2026-48853 — Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unau...
- CVE-2026-50889 — An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending ... (7.5 HIGH)