3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-26341
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.

CVE-2021-26330
1st Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-122 1 PoC

AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.

CVE-2021-25416
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-94 1 PoC

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.

CVE-2021-25847
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to controllable loop counter variable via a crafted lldp packet.

CVE-2021-23839
OpenSSL General
N/A
UNKNOWN
EPSS
0.3%
2021 5 PoCs

OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A server that supports greater than SSLv2 is supposed to reject connection attempts from a client where this special form of padding is present, because this indicates that a version rollback has occurred (i.e. both client and server support great

CVE-2021-46771
3rd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 1 PoC

Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.

CVE-2021-27195
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic.

CVE-2021-30953
watchOS General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2021-26400
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple processors are operating on shared memory, resulting in potential data leakage.

CVE-2021-33057
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.

CVE-2021-25171
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetlicensecfg function.

CVE-2021-38378
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.

CVE-2021-40088
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.

CVE-2021-42682
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 .The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-0510
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-176444622

CVE-2021-43396
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 3 PoCs

In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be invoked through user input and requires iconv to be invoked with a NULL inbuf, which ought to require a separate application bug to do so unintentionally. Hence there's no security impact to the bug.

CVE-2021-36580
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
10.0%
2021 2 PoCs

Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.

CVE-2021-36706
Software Genérico General
N/A
UNKNOWN
EPSS
13.1%
2021 1 PoC

In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to system.

CVE-2021-47760
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-28142
Software Genérico General
N/A
UNKNOWN
EPSS
4.0%
2021 1 PoC

CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."