3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-46611
MicroStation CONNECT General
3.3
LOW
EPSS
0.5%
2021 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the cu

CVE-2021-27262
PhantomPDF General
3.3
LOW
EPSS
11.4%
2021 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the con

CVE-2021-25458
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2021 CWE-476 1 PoC

NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.

CVE-2021-27264
PhantomPDF General
3.3
LOW
EPSS
11.4%
2021 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.1.0.37527. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the con

CVE-2021-46600
MicroStation CONNECT General
3.3
LOW
EPSS
0.5%
2021 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the curr

CVE-2021-31447
Reader General
3.3
LOW
EPSS
13.0%
2021 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context

CVE-2021-34889
View General
3.3
LOW
EPSS
0.5%
2021 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Wa

CVE-2021-25505
Samsung Pass General
3.3
LOW
EPSS
0.1%
2021 CWE-287 1 PoC

Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.

CVE-2021-23896
McAfee Database Security (DBSec) General
3.2
LOW
EPSS
0.0%
2021 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.

CVE-2021-25366
Samsung Internet General
3.2
LOW
EPSS
0.1%
2021 CWE-703 2 PoCs

Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.

CVE-2021-25333
Samsung Pay Mini General
3.2
LOW
EPSS
0.1%
2021 CWE-200 2 PoCs

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.

CVE-2021-25351
Samsung Account General
3.2
LOW
EPSS
0.0%
2021 CWE-285 2 PoCs

Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.

CVE-2021-25331
Samsung Pay Mini General
3.2
LOW
EPSS
0.1%
2021 CWE-200 2 PoCs

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.

CVE-2021-25332
Samsung Pay Mini General
3.2
LOW
EPSS
0.1%
2021 CWE-200 2 PoCs

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.

CVE-2021-21592
PowerScale OneFS General
3.1
LOW
EPSS
0.2%
2021 CWE-755 1 PoC

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.

CVE-2021-22151
Kibana General
3.1
LOW
EPSS
0.6%
2021 CWE-22 1 PoC

It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.

CVE-2021-23445
datatables.net General
3.1
LOW
EPSS
0.3%
2021 3 PoCs

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

CVE-2021-25454
Samsung Mobile Devices General
3.1
LOW
EPSS
0.1%
2021 CWE-125 1 PoC

OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.

CVE-2021-23472
bootstrap-table General
3.1
LOW
EPSS
0.6%
2021 6 PoCs

This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.

CVE-2021-25376
Samsung Email General
3.1
LOW
EPSS
0.2%
2021 CWE-200 2 PoCs

An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.