3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-25493
Samsung Notes General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read

CVE-2021-25484
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-287 1 PoC

Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.

CVE-2021-25460
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-285 1 PoC

An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.

CVE-2021-25519
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-200 1 PoC

An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.

CVE-2021-25379
Gallery General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-926 2 PoCs

Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.

CVE-2021-25506
Samsung Health General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-287 1 PoC

Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.

CVE-2021-21781
Linux Kernel General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-908 2 PoCs

An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11

CVE-2021-25390
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-926 2 PoCs

Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

CVE-2021-25524
Contacts General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-922 1 PoC

Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.

CVE-2021-25521
Samsung Internet General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-285 1 PoC

Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.

CVE-2021-25341
S Assistant General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-287 2 PoCs

Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-25504
Group Sharing General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-20 1 PoC

Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.

CVE-2021-45640
Software Genérico General
3.9
LOW
EPSS
0.6%
2021 1 PoC

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1.1.00.34, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0.1.74, D7000v2 before 1.0.0.53, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DC112A before 1.0.0.42, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, DM200 before 1.0.0.61, EX3700 before 1.0.0.76, EX3800 before 1.0.0.76, EX6120 before 1.0.0.46, EX6130 before 1.0.0.28, EX7000 before 1.0.1.78, PR2000 before 1.0.0.28, R6220 before 1.1.0.100, R6230 before 1.1.0

CVE-2021-34395
NVIDIA Jetson TX1 General
3.9
LOW
EPSS
0.0%
2021 1 PoC

Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcations to data, and limited denial of service.

CVE-2021-46762
2nd Gen AMD EPYC™ General
3.9
LOW
EPSS
0.0%
2021 2 PoCs

Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.

CVE-2021-25475
Samsung Mobile Devices General
3.9
LOW
EPSS
0.0%
2021 CWE-122 1 PoC

A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

CVE-2021-32556
apport General
3.8
LOW
EPSS
0.1%
2021 CWE-78 1 PoC

It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.

CVE-2021-25527
Samsung Pay General
3.8
LOW
EPSS
0.1%
2021 CWE-926 1 PoC

Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.

CVE-2021-20582
Security Secret Server General
3.7
LOW
EPSS
0.2%
2021 1 PoC

IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 199328.

CVE-2021-22173
Wireshark General
3.7
LOW
EPSS
0.5%
2021 1 PoC

Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file