3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-41054
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.

CVE-2021-29154
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.

CVE-2021-44828
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Arm Mali GPU Kernel Driver (Midgard r26p0 through r30p0, Bifrost r0p0 through r34p0, and Valhall r19p0 through r34p0) allows a non-privileged user to achieve write access to read-only memory, and possibly obtain root privileges, corrupt memory, and modify the memory of other processes.

CVE-2021-32066
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVE-2021-43290
Software Genérico General
N/A
UNKNOWN
EPSS
3.7%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.

CVE-2021-0511
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-178055795

CVE-2021-44508
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.

CVE-2021-38291
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

CVE-2021-45901
Software Genérico General
N/A
UNKNOWN
EPSS
19.6%
2021 4 PoCs

The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.

CVE-2021-26807
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DLL loading.

CVE-2021-29983
Firefox General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91.

CVE-2021-37424
Software Genérico General
N/A
UNKNOWN
EPSS
13.6%
2021 1 PoC

ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.

CVE-2021-25804
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.

CVE-2021-38823
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.

CVE-2021-25424
Tizen wearable devices General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-287 1 PoC

Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.

CVE-2021-38569
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.

CVE-2021-25829
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2021 1 PoC

An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.

CVE-2021-28093
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.

CVE-2021-29657
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass access control on host OS MSRs when there are nested guests, aka CID-a58d9166a756. This occurs because of a TOCTOU race condition associated with a VMCB12 double fetch in nested_svm_vmrun.

CVE-2021-35309
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.