3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-38570
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (during uninstallation) via a symlink.

CVE-2021-26369
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

CVE-2021-29060
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.

CVE-2021-0394
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-172655291

CVE-2021-42986
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

NoMachine Enterprise Client is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Client above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-3802
udisks2 General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 1 PoC

A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.

CVE-2021-45092
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.4%
2021 1 PoC

Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

CVE-2021-33333
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions via crafted URLs.

CVE-2021-39363
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.

CVE-2021-38209
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL_CT_EXPECT_MAX, and NF_SYSCTL_CT_BUCKETS sysctls.

CVE-2021-38204
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.

CVE-2021-38586
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).

CVE-2021-40085
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2021 1 PoC

An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.

CVE-2021-3659
Kernel General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-252 1 PoC

A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability.

CVE-2021-26597
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.

CVE-2021-26341
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.

CVE-2021-26330
1st Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-122 1 PoC

AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.

CVE-2021-25416
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-94 1 PoC

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.

CVE-2021-25847
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to controllable loop counter variable via a crafted lldp packet.

CVE-2021-23839
OpenSSL General
N/A
UNKNOWN
EPSS
0.3%
2021 5 PoCs

OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A server that supports greater than SSLv2 is supposed to reject connection attempts from a client where this special form of padding is present, because this indicates that a version rollback has occurred (i.e. both client and server support great