3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-31400
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-data processing function invokes a panic function if the pointer to the end of the out-of-band data points outside of the TCP segment's data. If the panic function hadn't a trap invocation removed, it will enter an infinite loop and therefore cause DoS (continuous loop or a device reset).

CVE-2021-29294
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicious user cause a denial of service via the send_hnap_unauthorized function. It could be triggered by sending crafted POST request to /HNAP1/. NOTE: The DSL-2740R and all hardware revisions are considered End of Life and as such this issue will not be patched

CVE-2021-22495
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) (Exynos chipsets) software. The Mali GPU driver allows out-of-bounds access and a device reset. The Samsung ID is SVE-2020-19174 (January 2021).

CVE-2021-32571
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Ericsson Network Manager is a new generation OSS system which OSS-RC customers shall upgrade to

CVE-2021-3380
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print Invoice Functionality.

CVE-2021-41772
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.

CVE-2021-28972
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.

CVE-2021-3541
libxml2 General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.

CVE-2021-44582
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.

CVE-2021-40658
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.

CVE-2021-41390
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.

CVE-2021-44533
Node General
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-295 2 PoCs

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous pr

CVE-2021-30028
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.

CVE-2021-42192
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
23.5%
2021 1 PoC

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

CVE-2021-27188
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.

CVE-2021-36231
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.

CVE-2021-43538
Thunderbird General
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVE-2021-44155
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is invalid. This allows an attacker to enumerate valid users.

CVE-2021-45892
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.

CVE-2021-31826
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.