9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-21980
3rd Gen AMD EPYC™ Processors General
7.9
HIGH
EPSS
2.3%
2024 CWE-119 1 PoC

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.

CVE-2024-46975
Graphics DDK General
7.9
HIGH
EPSS
0.0%
2024 CWE-270 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.

CVE-2024-33469
Software Genérico General
7.9
HIGH
EPSS
0.2%
2024 1 PoC

An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java.

CVE-2019-9500
brcmfmac WiFi driver General
7.9
HIGH
EPSS
2.9%
2019 CWE-122 2 PoCs

The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitr

CVE-2019-9502
WiFi drivers General
7.9
HIGH
EPSS
1.4%
2019 CWE-122 2 PoCs

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

CVE-2019-9503
brcmfmac WiFi driver General
7.9
HIGH
EPSS
0.5%
2019 CWE-20 3 PoCs

The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfmac driver receives a firmware event frame from a remote source, the is_wlc_event_frame function will cause this frame to be discarded and unprocessed. If the driver receives the firmware event frame from the host, the appropriate handler is called. This frame validation can be bypassed if the bus used is USB (for instance by a wifi dongle). This can allow firmware event frames from a remote source to be processed. In the worst case scenario, by sen

CVE-2019-9501
WiFi drivers General
7.9
HIGH
EPSS
2.3%
2019 CWE-122 2 PoCs

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

CVE-2019-20652
Software Genérico General
7.9
HIGH
EPSS
0.1%
2019 1 PoC

NETGEAR WAC505 devices before 8.2.1.16 are affected by disclosure of sensitive information.

CVE-2021-25502
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-269 1 PoC

A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.

CVE-2021-25361
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-22 2 PoCs

An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.

CVE-2021-34373
NVIDIA Jetson TX1 General
7.9
HIGH
EPSS
0.1%
2021 1 PoC

Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could cause heap overflows, which might lead to information disclosure and denial of service.

CVE-2021-25470
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-94 1 PoC

An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

CVE-2021-45649
Software Genérico General
7.9
HIGH
EPSS
0.1%
2021 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R7000 before 1.0.11.126, R6900P before 1.3.2.126, and R7000P before 1.3.2.126.

CVE-2020-5245
dropwizard-validation General
7.9
HIGH
EPSS
6.3%
2020 CWE-74 2 PoCs

Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.

CVE-2022-24931
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2022 CWE-269 1 PoC

Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbitrary activity without a proper permission

CVE-2022-1714
radareorg/radare2 General
7.9
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

CVE-2022-1823
McAfee Consumer Product Removal Tool General
7.9
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code, through not correctly checking the integrity of the configuration file.

CVE-2022-1824
McAfee Consumer Product Removal Tool General
7.9
HIGH
EPSS
0.2%
2022 CWE-427 1 PoC

An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to execute arbitrary code as there were insufficient checks on the executable being signed by McAfee.

CVE-2014-3153
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
68.9%
2014 6 PoCs

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

CVE-2013-2596
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
3.1%
2013 3 PoCs

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.