3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-30956
iOS and iPadOS General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker with physical access to a device may be able to see private contact information.

CVE-2021-37819
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.

CVE-2021-46310
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered IW44Image.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.

CVE-2021-46226
Software Genérico General
N/A
UNKNOWN
EPSS
5.8%
2021 1 PoC

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.

CVE-2021-44444
JT Utilities General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-125 1 PoC

A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-15052)

CVE-2021-46703
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2021 1 PoC

In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-20718
mod_auth_openidc General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.

CVE-2021-24288
Newsletter via SMTP, Sendinblue, Sendgrid, Mailgun - AcyMailing SMTP Newsletter General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2021 CWE-601 1 PoC

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

CVE-2021-41794
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can send a PFCP Session Establishment Request with "internet" as the PDI Network Instance. The first character is interpreted as a length value to be used in a memcpy call. The destination buffer is only 100 bytes long on the stack. Then, 'i' gets interpreted as 105 bytes to copy from the source buffer to the destination buffer.

CVE-2021-26758
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2021 2 PoCs

Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.

CVE-2021-27135
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 2 PoCs

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

CVE-2021-44502
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to util_format in sr_unix/util_output.c.

CVE-2021-43734
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
77.4%
2021 0 PoCs

kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.

CVE-2021-33320
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 5, does not limit the rate at which content can be flagged as inappropriate, which allows remote authenticated users to spam the site administrator with emails

CVE-2021-26368
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service.

CVE-2021-26340
AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).

CVE-2021-1066
NVIDIA Virtual GPU Manager General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to unexpected consumption of resources, which in turn may lead to denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-38200
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13, on systems with perf_event_paranoid=-1 and no specific PMU driver support registered, allows local users to cause a denial of service (perf_instruction_pointer NULL pointer dereference and OOPS) via a "perf record" command.

CVE-2021-25681
Software Genérico General
N/A
UNKNOWN
EPSS
12.6%
2021 2 PoCs

AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager web servers to be used as DNS redirectors to tunnel arbitrary data over DNS. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched

CVE-2021-38304
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Improper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to potentially enable escalation of privilege via local access.