3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-3973
vim/vim General
7.3
HIGH
EPSS
0.4%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-23403
ts-nodash General
7.3
HIGH
EPSS
0.5%
2021 1 PoC

All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validation input.

CVE-2021-25497
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2021 CWE-120 1 PoC

A possible buffer overflow vulnerability in maetd_cpy_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.

CVE-2021-23568
extend2 General
7.3
HIGH
EPSS
0.5%
2021 1 PoC

The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.

CVE-2021-38410
Platform Common Services (PCS) Portal General
7.3
HIGH
EPSS
0.1%
2021 1 PoC

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.

CVE-2021-23379
portkiller General
7.3
HIGH
EPSS
0.8%
2021 1 PoC

This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-45526
Software Genérico General
7.3
HIGH
EPSS
0.4%
2021 1 PoC

Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects EX6000 before 1.0.0.38, EX6120 before 1.0.0.48, EX6130 before 1.0.0.30, R6300v2 before 1.0.4.52, R6400 before 1.0.1.52, R7000 before 1.0.11.126, R7900 before 1.0.4.30, R8000 before 1.0.4.52, R7000P before 1.3.2.124, R8000P before 1.4.1.50, RAX80 before 1.0.3.88, R6900P before 1.3.2.124, R7900P before 1.4.1.50, and RAX75 before 1.0.3.88.

CVE-2021-25487
🔥 KEV Samsung Mobile Devices General
7.3
HIGH
EPSS
2.7%
2021 CWE-125 1 PoC

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

CVE-2021-37706
pjproject General
7.3
HIGH
EPSS
0.2%
2021 CWE-191 1 PoC

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s

CVE-2021-23375
psnode General
7.3
HIGH
EPSS
0.8%
2021 1 PoC

This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-3984
vim/vim General
7.3
HIGH
EPSS
0.2%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-32547
apport General
7.3
HIGH
EPSS
0.1%
2021 CWE-59 1 PoC

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.

CVE-2021-32549
apport General
7.3
HIGH
EPSS
0.1%
2021 CWE-59 1 PoC

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users.

CVE-2021-25495
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2021 CWE-122 1 PoC

A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.

CVE-2021-23402
record-like-deep-assign General
7.3
HIGH
EPSS
0.5%
2021 1 PoC

All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.

CVE-2021-23440
set-value General
7.3
HIGH
EPSS
0.1%
2021 4 PoCs

This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

CVE-2021-23682
litespeed.js General
7.3
HIGH
EPSS
5.4%
2021 2 PoCs

This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.

CVE-2021-1108
Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX, Jetson Nano, Jetson Nano 2GB, Jetson TX1 General
7.3
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack of input validation may lead to complete denial of service, partial integrity, and serious confidentiality loss for all processes in the system.

CVE-2021-32548
apport General
7.3
HIGH
EPSS
0.1%
2021 CWE-59 1 PoC

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users.

CVE-2021-4069
vim/vim General
7.3
HIGH
EPSS
0.2%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free