3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-25830
Software Genérico General
N/A
UNKNOWN
EPSS
6.1%
2021 1 PoC

A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer.

CVE-2021-38278
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.

CVE-2021-30047
Software Genérico General
N/A
UNKNOWN
EPSS
33.9%
2021 1 PoC

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

CVE-2021-42390
clickhouse General
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-369 1 PoC

Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

CVE-2021-29983
Firefox General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91.

CVE-2021-20072
Racom MIDGE Firmware General
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an authenticated directory traveral.

CVE-2021-25804
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.

CVE-2021-21156
Chrome General
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.

CVE-2021-35336
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.8%
2021 1 PoC

Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.

CVE-2021-28095
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.

CVE-2021-37157
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.

CVE-2021-37915
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from an attacker-defined host.

CVE-2021-35392
Software Genérico General
N/A
UNKNOWN
EPSS
73.6%
2021 1 PoC

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a heap buffer overflow that is present due to unsafe crafting of SSDP NOTIFY messages from received M-SEARCH messages ST header.

CVE-2021-37761
Software Genérico General
N/A
UNKNOWN
EPSS
37.4%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.

CVE-2021-46067
Software Genérico General
N/A
UNKNOWN
EPSS
14.1%
2021 1 PoC

In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

CVE-2021-42739
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.

CVE-2021-43469
Software Genérico General
N/A
UNKNOWN
EPSS
9.4%
2021 1 PoC

VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.

CVE-2021-42377
busybox General
N/A
UNKNOWN
EPSS
2.9%
2021 CWE-590 2 PoCs

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

CVE-2021-32919
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).

CVE-2021-28855
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

In Deark before 1.5.8, a specially crafted input file can cause a NULL pointer dereference in the dbuf_write function (src/deark-dbuf.c).