3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-3881
bfabiszewski/libmobi General
7.1
HIGH
EPSS
0.4%
2021 CWE-125 1 PoC

libmobi is vulnerable to Out-of-bounds Read

CVE-2021-45448
Pentaho Business Analytics Server General
7.1
HIGH
EPSS
0.4%
2021 CWE-22 1 PoC

Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user-supplied path to access resources that are out of bounds.  The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.  By using special eleme

CVE-2021-25346
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.6%
2021 2 PoCs

A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

CVE-2021-26402
2nd Gen EPYC General
7.1
HIGH
EPSS
0.1%
2021 1 PoC

Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability.

CVE-2021-3889
bfabiszewski/libmobi General
7.1
HIGH
EPSS
0.1%
2021 CWE-823 1 PoC

libmobi is vulnerable to Use of Out-of-range Pointer Offset

CVE-2021-27272
ProSAFE Network Management System General
7.1
HIGH
EPSS
69.0%
2021 CWE-22 1 PoC

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ReportTemplateController class. When parsing the path parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12123.

CVE-2021-27276
ProSAFE Network Management System General
7.1
HIGH
EPSS
59.0%
2021 CWE-22 1 PoC

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the MibController class. When parsing the realName parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12122.

CVE-2021-26397
3rd Gen AMD EPYC™ General
7.1
HIGH
EPSS
0.0%
2021 1 PoC

Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.

CVE-2021-30283
Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
7.1
HIGH
EPSS
0.0%
2021 1 PoC

Possible denial of service due to improper handling of debug register trap from user applications in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2021-1935
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables General
7.1
HIGH
EPSS
0.0%
2021 1 PoC

Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-45658
Software Genérico General
7.1
HIGH
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6100v2 before 1.0.1.86, EX6200v2 before 1.0.1.78, EX6250 before 1.0.0.110, EX6410 before 1.0.0.110, EX6420 before 1.0.0.110, EX6400v2 before 1.0.0.110, EX7300 before 1.0.2.144, EX6400 before 1.0.2.144, EX7320 before 1.0.0.110, EX7300v2 before 1.0.0.110, R7500v2 before 1.0.3.48, R7800 before 1.0.2.68, R8900 before 1.0.5.2, R9000 before 1.0.5.2, RAX120 before 1.0.1.90, RBK40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 befo

CVE-2021-40425
Secure Anywhere General
7.1
HIGH
EPSS
0.0%
2021 CWE-125 1 PoC

An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. An IOCTL_B03 request with specific invalid data causes a similar issue in the device driver WRCore_x64. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2021-25356
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2021 CWE-20 3 PoCs

An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.

CVE-2021-4019
vim/vim General
7.1
HIGH
EPSS
0.3%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-31601
Software Genérico General
7.1
HIGH
EPSS
2.1%
2021 1 PoC

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all databases connection details and credentials.

CVE-2021-25388
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2021 CWE-926 2 PoCs

Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.

CVE-2021-45659
Software Genérico General
7.1
HIGH
EPSS
0.1%
2021 1 PoC

Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40.

CVE-2021-46779
1st Gen EPYC General
7.1
HIGH
EPSS
0.1%
2021 1 PoC

Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.

CVE-2021-4166
vim/vim General
7.1
HIGH
EPSS
0.4%
2021 CWE-125 1 PoC

vim is vulnerable to Out-of-bounds Read

CVE-2021-21315
🔥 KEV systeminformation General ⚡ nuclei
7.1
HIGH
EPSS
94.0%
2021 CWE-78 6 PoCs

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.