3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-35093
BlueCore General
6.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial of service in BlueCore

CVE-2021-23429
transpile General
6.5
MEDIUM
EPSS
0.3%
2021 1 PoC

All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception handling in the .to() function.

CVE-2021-41182
jquery-ui General
6.5
MEDIUM
EPSS
27.5%
2021 CWE-79 5 PoCs

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

CVE-2021-4026
bookstackapp/bookstack General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-284 1 PoC

bookstack is vulnerable to Improper Access Control

CVE-2021-45495
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2021 1 PoC

NETGEAR D7000 devices before 1.0.1.68 are affected by authentication bypass.

CVE-2021-21439
((OTRS)) Community Edition General
6.5
MEDIUM
EPSS
0.3%
2021 CWE-754 1 PoC

DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions; 8.0.x version 8.0.13 and prior versions.

CVE-2021-3709
apport General
6.5
MEDIUM
EPSS
0.1%
2021 CWE-538 2 PoCs

Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file. This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versions prior to 2.20.1-0ubuntu2.30+esm2; 2.20.9 versions prior to 2.20.9-0ubuntu7.26; 2.20.11 versions prior to 2.20.11-0ubuntu27.20; 2.20.11 versions prior to 2.20.11-0ubuntu65.3;

CVE-2021-41788
Software Genérico General
6.5
MEDIUM
EPSS
0.5%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).

CVE-2021-3989
star7th/showdoc General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-601 1 PoC

showdoc is vulnerable to URL Redirection to Untrusted Site

CVE-2021-23700
merge-deep2 General
6.5
MEDIUM
EPSS
0.5%
2021 1 PoC

All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.

CVE-2021-30348
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music General
6.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

CVE-2021-3485
Endpoint Security Tools for Linux General
6.4
MEDIUM
EPSS
0.8%
2021 CWE-494 1 PoC

An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.

CVE-2021-25518
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.0%
2021 CWE-119 1 PoC

An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.

CVE-2021-36100
OTRS General
6.4
MEDIUM
EPSS
0.7%
2021 1 PoC

Specially crafted string in OTRS system configuration can allow the execution of any system command.

CVE-2021-25516
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2021 CWE-703 1 PoC

An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.

CVE-2021-34383
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
6.4
MEDIUM
EPSS
0.1%
2021 1 PoC

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might lead to denial of service or escalation of privileges.

CVE-2021-36290
VNX2 General
6.4
MEDIUM
EPSS
0.0%
2021 CWE-732 1 PoC

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain privileges.

CVE-2021-25394
🔥 KEV Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.4%
2021 CWE-416 1 PoC

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

CVE-2021-25481
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.0%
2021 CWE-754 1 PoC

An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP Memory.

CVE-2021-23556
guake General
6.4
MEDIUM
EPSS
0.8%
2021 1 PoC

The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes it possible for a malicious user to run an arbitrary command via the d-bus method. **Note:** Exploitation requires the user to have installed another malicious program that will be able to send dbus signals or run terminal commands.