3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-25373
Customization Service General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-285 2 PoCs

Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

CVE-2021-25452
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-22 1 PoC

An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.

CVE-2021-27562
🔥 KEV Software Genérico General
5.5
MEDIUM
EPSS
44.5%
2021 1 PoC

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

CVE-2021-4192
vim/vim General
5.5
MEDIUM
EPSS
0.6%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2021-46791
3rd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted SMM executable binary to corrupt Dynamic Root of Trust for Measurement (DRTM) user application memory that may result in a potential denial of service.

CVE-2021-25352
Bixby Voice General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-285 2 PoCs

Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.

CVE-2021-4193
vim/vim General
5.5
MEDIUM
EPSS
0.6%
2021 CWE-125 1 PoC

vim is vulnerable to Out-of-bounds Read

CVE-2021-30657
🔥 KEV macOS General
5.5
MEDIUM
EPSS
83.1%
2021 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

CVE-2021-25334
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-20 2 PoCs

Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent denial of service.

CVE-2021-25355
Samsung Notes General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-285 2 PoCs

Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.

CVE-2021-4183
Wireshark General
5.5
MEDIUM
EPSS
0.2%
2021 1 PoC

Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file

CVE-2021-47631
Linux General
5.5
MEDIUM
EPSS
0.0%
2021 1 PoC

In the Linux kernel, the following vulnerability has been resolved: ARM: davinci: da850-evm: Avoid NULL pointer dereference With newer versions of GCC, there is a panic in da850_evm_config_emac() when booting multi_v5_defconfig in QEMU under the palmetto-bmc machine: Unable to handle kernel NULL pointer dereference at virtual address 00000020 pgd = (ptrval) [00000020] *pgd=00000000 Internal error: Oops: 5 [#1] PREEMPT ARM Modules linked in: CPU: 0 PID: 1 Comm: swapper Not tainted 5.15.0 #1 Hardware name: Generic DT based system PC is at da850_evm_config_emac+0x1c/0x120 LR is at do_one_initc

CVE-2021-25488
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-125 1 PoC

Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.

CVE-2021-26404
3rd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

CVE-2021-33910
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2021 2 PoCs

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

CVE-2021-28507
EOS General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-284 1 PoC

An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.

CVE-2021-27414
Ellipse Enterprise Asset Management (EAM) General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-451 1 PoC

An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials.

CVE-2021-34600
CompasX General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-335 2 PoCs

Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.

CVE-2021-25456
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.

CVE-2021-4245
rfc6902 General
5.5
MEDIUM
EPSS
0.7%
2021 CWE-74 1 PoC

A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The exploit has been disclosed to the public and may be used. The name of the patch is c006ce9faa43d31edb34924f1df7b79c137096cf. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215883.