{"api_version":"1","generated_at":"2026-07-25T00:16:19+00:00","cve":"CVE-2021-36134","urls":{"html":"https://cve.report/CVE-2021-36134","api":"https://cve.report/api/cve/CVE-2021-36134.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-36134","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-36134"},"summary":{"title":"CVE-2021-36134","description":"Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-09-27 17:15:00","updated_at":"2021-10-04 19:25:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"https://www.mcafee.com/blogs/?p=127255&preview=true","name":"https://www.mcafee.com/blogs/?p=127255&preview=true","refsource":"MISC","tags":[],"title":"Finding 0-days with Jackalope | McAfee Blogs","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-36134","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-36134","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Douglas McKee of McAfee ATR","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"36134","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"36134","vulnerable":"1","versionEndIncluding":"9.7.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netop","cpe5":"vision_pro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-36134","STATE":"PUBLIC","TITLE":"Out of bounds write in Netop Vision Pro"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"credit":[{"lang":"eng","value":"Douglas McKee of McAfee ATR"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS)."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":7.4,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.mcafee.com/blogs/?p=127255&preview=true","url":"https://www.mcafee.com/blogs/?p=127255&preview=true"}]},"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-09-27 17:15:00","lastModifiedDate":"2021-10-04 19:25:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:N/I:N/A:P","accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":3.3},"severity":"LOW","exploitabilityScore":6.5,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netop:vision_pro:*:*:*:*:*:*:*:*","versionEndIncluding":"9.7.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"36134","Ordinal":"211673","Title":"CVE-2021-36134","CVE":"CVE-2021-36134","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"36134","Ordinal":"1","NoteData":"Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS).","Type":"Description","Title":null},{"CveYear":"2021","CveId":"36134","Ordinal":"2","NoteData":"2021-09-27","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"36134","Ordinal":"3","NoteData":"2021-09-27","Type":"Other","Title":"Modified"}]}}}