3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-3759
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-400 1 PoC

A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability.

CVE-2021-41318
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

CVE-2021-4157
kernel General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-119 1 PoC

An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system.

CVE-2021-4002
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-459 4 PoCs

A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.

CVE-2021-31795
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allows attackers to overwrite heap memory via PhysmemNewRamBackedPMR.

CVE-2021-26272
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 3 PoCs

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

CVE-2021-1810
macOS General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks.

CVE-2021-45998
Software Genérico General
N/A
UNKNOWN
EPSS
5.8%
2021 1 PoC

D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

CVE-2021-25801
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

CVE-2021-26372
EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

CVE-2021-40529
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVE-2021-33515
Software Genérico General
N/A
UNKNOWN
EPSS
5.9%
2021 1 PoC

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVE-2021-44879
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.

CVE-2021-41038
@theia/plugin-ext General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-940 1 PoC

In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().

CVE-2021-25264
Intercept X for MacOS General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.

CVE-2021-31613
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle the reception of a truncated LMP packet during the LMP auto rate procedure, allowing attackers in radio range to immediately crash (and restart) a device via a crafted LMP packet.

CVE-2021-37165
Software Genérico General
N/A
UNKNOWN
EPSS
5.0%
2021 1 PoC

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code execution.

CVE-2021-20157
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

It is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative command.

CVE-2021-26384
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI resulting in a potential loss of resources.

CVE-2021-41821
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.