3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-39009
Cognos Analytics General
4.4
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.

CVE-2021-25468
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory address.

CVE-2021-25473
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2021 CWE-755 1 PoC

Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.

CVE-2021-23331
com.squareup:connect General
4.4
MEDIUM
EPSS
0.0%
2021 1 PoC

This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary file with the permissions bits of -rw-r--r-- on unix-like systems. On unix-like systems, the system temporary directory is shared between users. As such, the contents of the file downloaded by downloadFileFromResponse will be visible to all other users on the local system. A workaround fix for this issue is to set the system property java.io.tmpdir to a safe directory as remediation. Note: This version of the SDK is end of life and no longer maintained, please upgrade to the lat

CVE-2021-25474
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2021 CWE-755 1 PoC

Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.

CVE-2021-1103
NVIDIA Virtual GPU Software General
4.4
MEDIUM
EPSS
0.0%
2021 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-25339
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2021 CWE-20 2 PoCs

Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corrupt EL2 memory.

CVE-2021-1114
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
4.4
MEDIUM
EPSS
0.1%
2021 1 PoC

NVIDIA Linux kernel distributions contain a vulnerability in the kernel crypto node, where use after free may lead to complete denial of service.

CVE-2021-25338
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2021 CWE-20 2 PoCs

Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region.

CVE-2021-25477
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.2%
2021 CWE-415 1 PoC

An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.

CVE-2021-32489
Software Genérico General
4.4
MEDIUM
EPSS
1.0%
2021 1 PoC

An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device because response_msg.st.len=8 can be accepted but triggers an integer overflow, which causes CRYPTO_cbc128_decrypt (in OpenSSL) to encounter an undersized buffer and experience a segmentation fault. The yubihsm-shell project is included in the YubiHSM 2 SDK product.

CVE-2021-25480
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.3%
2021 CWE-294 1 PoC

A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network connection.

CVE-2021-26396
3rd Gen EPYC General
4.4
MEDIUM
EPSS
0.0%
2021 1 PoC

Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.

CVE-2021-27593
SAP 3D Visual Enterprise Viewer General
4.3
MEDIUM
EPSS
0.2%
2021 1 PoC

When a user opens manipulated Graphics Interchange Format (.GIF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2021-4221
Firefox General
4.3
MEDIUM
EPSS
0.2%
2021 1 PoC

If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*<br>*Note*: Due to a clerical error this advisory was not included in the original announcement, and was added in Feburary 2022. This vulnerability affects Firefox < 92.

CVE-2021-41351
Microsoft Edge (Chromium-based) in IE Mode General
4.3
MEDIUM
EPSS
12.3%
2021 2 PoCs

Microsoft Edge (Chrome based) Spoofing on IE Mode

CVE-2021-38874
QRadar SIEM General
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397.

CVE-2021-4177
livehelperchat/livehelperchat General
4.3
MEDIUM
EPSS
0.3%
2021 CWE-209 1 PoC

livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

CVE-2021-41613
Software Genérico General
4.3
MEDIUM
EPSS
0.4%
2021 1 PoC

An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The write logic of Exception Effective Address Register (EEAR) is not implemented correctly. User programs from authorized privilege levels will be unable to write to EEAR.

CVE-2021-4089
snipe/snipe-it General
4.3
MEDIUM
EPSS
0.2%
2021 CWE-284 1 PoC

snipe-it is vulnerable to Improper Access Control