QSearchQSearch

CVE-2021-38477

9.8 CRITICAL

There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the mani...

Published: 2021-10-22 · Last updated: 2026-06-17

Severity and scoring

CVSS
9.8 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-73

Affected products

VendorProduct
auvesyversiondog

Description

There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-38481 The scheduler service running on a specific TCP port enables the user to start and stop jobs (8.1 HIGH)
  • CVE-2021-38479 Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory regions (6.5 MEDIUM)
  • CVE-2021-38475 The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permi... (7.3 HIGH)
  • CVE-2021-38473 The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack overflow (8.0 HIGH)
  • CVE-2021-38471 There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or creat... (9.1 CRITICAL)

Same CWE

  • CVE-2026-10303 In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 be... (7.4 HIGH)
  • CVE-2026-39006 An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component (9.8 CRITICAL)
  • CVE-2026-34030 The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code when a new branch i...
  • CVE-2026-11527 Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument... (8.6 HIGH)
  • CVE-2026-11526 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle (9.8 CRITICAL)