3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-21944
ImageGear General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-122 1 PoC

Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer oveflow takes place trying to copy the first 12 bits from local variable.

CVE-2021-46760
3rd Gen AMD Ryzen™ Threadripper™ Processors “Castle Peak” HEDT General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achieving code execution.

CVE-2021-34569
750-81xx/xxx-xxxFW General
9.8
CRITICAL
EPSS
0.2%
2021 CWE-787 1 PoC

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

CVE-2021-36380
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2021 1 PoC

Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.

CVE-2021-23390
total4 General
9.8
CRITICAL
EPSS
1.3%
2021 1 PoC

The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

CVE-2021-21795
Accusoft General
9.8
CRITICAL
EPSS
0.5%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the PSD read_icc_icCurve_data functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an integer overflow that, in turn, leads to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21939
ImageGear General
9.8
CRITICAL
EPSS
1.2%
2021 CWE-120 1 PoC

A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-1920
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-21782
Accusoft General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-131 1 PoC

An out-of-bounds write vulnerability exists in the SGI format buffer size processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-25928
safe-obj General
9.8
CRITICAL
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-25981
talkyard General
9.8
CRITICAL
EPSS
2.1%
2021 CWE-613 1 PoC

In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain that token (via other, hypothetical attacks)

CVE-2021-25927
safe-flat General
9.8
CRITICAL
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-26379
2nd Gen AMD EPYC™ General
9.8
CRITICAL
EPSS
0.2%
2021 1 PoC

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.

CVE-2021-3177
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2021 6 PoCs

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.

CVE-2021-1946
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
9.8
CRITICAL
EPSS
0.2%
2021 1 PoC

Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2021-33045
🔥 KEV Some Dahua IP Camera, Video Intercom, NVR, XVR devices General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2021 3 PoCs

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

CVE-2021-21946
ImageGear General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-122 1 PoC

Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer overflow takes place when the `SOF3` precision is lower than 9.

CVE-2021-21794
Accusoft" General
9.8
CRITICAL
EPSS
0.2%
2021 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the TIF bits_per_sample processing functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-20090
🔥 KEV Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 2 PoCs

A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.

CVE-2021-36294
VNX Control Station General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-331 1 PoC

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.