3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-0510
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-176444622

CVE-2021-43396
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 3 PoCs

In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be invoked through user input and requires iconv to be invoked with a NULL inbuf, which ought to require a separate application bug to do so unintentionally. Hence there's no security impact to the bug.

CVE-2021-36580
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
10.0%
2021 2 PoCs

Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.

CVE-2021-36706
Software Genérico General
N/A
UNKNOWN
EPSS
13.1%
2021 1 PoC

In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to system.

CVE-2021-44848
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
61.0%
2021 1 PoC

In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.

CVE-2021-47760
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-28142
Software Genérico General
N/A
UNKNOWN
EPSS
4.0%
2021 1 PoC

CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."

CVE-2021-32066
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails with an an unknown response, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVE-2021-3544
QEMU General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-401 1 PoC

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.

CVE-2021-3254
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.

CVE-2021-25306
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.

CVE-2021-25830
Software Genérico General
N/A
UNKNOWN
EPSS
6.1%
2021 1 PoC

A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer.

CVE-2021-38278
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.

CVE-2021-30047
Software Genérico General
N/A
UNKNOWN
EPSS
33.9%
2021 1 PoC

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

CVE-2021-42390
clickhouse General
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-369 1 PoC

Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

CVE-2021-21156
Chrome General
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.

CVE-2021-35336
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.8%
2021 1 PoC

Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.

CVE-2021-28095
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.

CVE-2021-37157
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.

CVE-2021-37915
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from an attacker-defined host.