3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-39246
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or collected by a rogue site within the Tor network).

CVE-2021-3802
udisks2 General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 1 PoC

A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.

CVE-2021-0334
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-163358811

CVE-2021-26378
EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

CVE-2021-25447
Smart Things General
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-284 1 PoC

Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.

CVE-2021-36761
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.

CVE-2021-45092
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.4%
2021 1 PoC

Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

CVE-2021-38206
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers to cause a denial of service (NULL pointer dereference in the radiotap parser) by injecting a frame with 802.11a rates.

CVE-2021-38179
SAP Business One General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contents which may include User credentials.

CVE-2021-25948
expand-hash General
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-42098
Remote Desktop Manager General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.

CVE-2021-44964
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

CVE-2021-4037
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-284 2 PoCs

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.

CVE-2021-25777
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.

CVE-2021-43033
Software Genérico General
N/A
UNKNOWN
EPSS
11.0%
2021 3 PoCs

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server) being passed to system calls.

CVE-2021-44494
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

CVE-2021-46019
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

CVE-2021-34150
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic implementation on Bluetrum AB5301A devices with unknown firmware versions does not properly handle the reception of oversized DM1 LMP packets while no other BT connections are active, allowing attackers in radio range to prevent new BT connections (disabling the AB5301A inquiry and page scan procedures) via a crafted LMP packet. The user needs to manually perform a power cycle (restart) of the device to restore BT connectivity.

CVE-2021-25408
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-787 1 PoC

A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.

CVE-2021-27362
Software Genérico General
N/A
UNKNOWN
EPSS
4.2%
2021 1 PoC

The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to execute arbitrary code.