3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-43199
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.

CVE-2021-31829
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.

CVE-2021-43293
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).

CVE-2021-44504
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted as a negative value during a check. This value is then used in a memcpy call on the stack, causing a memory segmentation fault.

CVE-2021-40490
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.

CVE-2021-44595
Software Genérico General
N/A
UNKNOWN
EPSS
8.2%
2021 3 PoCs

Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privileges.

CVE-2021-31224
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.

CVE-2021-3006
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access control and thus allows price manipulation, as exploited in the wild in December 2020 and January 2021.

CVE-2021-25405
Samsung Notes General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-284 1 PoC

An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access local files.

CVE-2021-4203
kernel General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-362 1 PoC

A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.

CVE-2021-30494
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log information. In other words, an attacker can create a file in an unintended directory (with some limitations).

CVE-2021-34143
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after paging procedure. User intervention is required to restart the device.

CVE-2021-42641
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.

CVE-2021-45897
Software Genérico General
N/A
UNKNOWN
EPSS
24.6%
2021 1 PoC

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.

CVE-2021-43180
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.

CVE-2021-0391
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In onCreate() of ChooseTypeAndAccountActivity.java, there is a possible way to learn the existence of an account, without permissions, due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-172841550

CVE-2021-34544
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive information to be read by someone with access to the device. Fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.

CVE-2021-3345
Software Genérico General
N/A
UNKNOWN
EPSS
5.7%
2021 3 PoCs

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

CVE-2021-36394
Moodle General
N/A
UNKNOWN
EPSS
11.6%
2021 CWE-384 2 PoCs

In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

CVE-2021-38094
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.