3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-21779
Webkit General
6.8
MEDIUM
EPSS
0.5%
2021 CWE-416 1 PoC

A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability.

CVE-2021-1895
Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music General
6.8
MEDIUM
EPSS
0.0%
2021 1 PoC

Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

CVE-2021-25397
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-926 2 PoCs

An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.

CVE-2021-45607
Software Genérico General
6.8
MEDIUM
EPSS
0.3%
2021 1 PoC

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, R6900P before 1.3.3.140, R7000 before 1.0.11.126, R7000P before 1.3.3.140, RAX200 before 1.0.5.126, RAX75 before 1.0.5.126, and RAX80 before 1.0.5.126.

CVE-2021-37577
Software Genérico General
6.8
MEDIUM
EPSS
0.0%
2021 1 PoC

Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the-middle attacker to identify the Passkey used during pairing by reflection of a crafted public key with the same X coordinate as the offered public key and by reflection of the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. This is a related issue t

CVE-2021-47786
Redragon Gaming Mouse General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-787 2 PoCs

Redragon Gaming Mouse driver contains a kernel-level vulnerability that allows attackers to trigger a denial of service by sending malformed IOCTL requests. Attackers can send a crafted 2000-byte buffer with specific byte patterns to the REDRAGON_MOUSE device to crash the kernel driver.

CVE-2021-21570
NetWorker General
6.8
MEDIUM
EPSS
0.4%
2021 CWE-78 1 PoC

Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

CVE-2021-21327
glpi General
6.8
MEDIUM
EPSS
0.3%
2021 CWE-862 1 PoC

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instantiate object of any class existing in the GLPI environment that can be used to carry out malicious attacks, or to start a “POP chain”. As an example of direct impact, this vulnerability affects integrity of the GLPI core platform and third-party plugins runtime misusing classes which implement some sensitive operations in their constructors or destructors. This is fixed in versio

CVE-2021-3645
viking04/merge General
6.8
MEDIUM
EPSS
0.5%
2021 CWE-1321 1 PoC

merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-38522
Software Genérico General
6.8
MEDIUM
EPSS
0.5%
2021 1 PoC

NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user.

CVE-2021-4173
vim/vim General
6.8
MEDIUM
EPSS
0.5%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2021-4188
mruby/mruby General
6.8
MEDIUM
EPSS
0.3%
2021 CWE-476 1 PoC

mruby is vulnerable to NULL Pointer Dereference

CVE-2021-38532
Software Genérico General
6.8
MEDIUM
EPSS
0.5%
2021 1 PoC

NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings.

CVE-2021-26928
Software Genérico General
6.8
MEDIUM
EPSS
0.3%
2021 1 PoC

BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route redirection for Denial of Service and/or Information Disclosure. NOTE: a researcher has asserted that the behavior is within Tigera’s area of responsibility; however, Tigera disagrees

CVE-2021-25362
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-269 2 PoCs

An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.

CVE-2021-47789
Yenkee Hornet Gaming Mouse General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-121 2 PoCs

Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash the system by sending oversized input. Attackers can exploit the driver by sending a 2000-byte buffer through DeviceIoControl to trigger a kernel-level system crash.

CVE-2021-25363
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-269 2 PoCs

An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.

CVE-2021-4187
vim/vim General
6.8
MEDIUM
EPSS
0.3%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2021-21353
pug General
6.8
MEDIUM
EPSS
1.9%
2021 CWE-74 1 PoC

Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was possible for them to achieve remote code execution on the node.js backend. This is fixed in version 3.0.1. This advisory applies to multiple pug packages including "pug", "pug-code-gen". pug-code-gen has a backported fix at version 2.0.3. This advisory is not exploitable if there is no way for un-