3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-3772
kernel General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-354 3 PoCs

A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.

CVE-2021-40497
SAP BusinessObjects Analysis, (edition for OLAP) General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation could lead to exposure of some system specific data like its version.

CVE-2021-42099
Software Genérico General
N/A
UNKNOWN
EPSS
22.4%
2021 1 PoC

Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

CVE-2021-40382
Software Genérico General
N/A
UNKNOWN
EPSS
39.5%
2021 1 PoC

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allows video screenshot access.

CVE-2021-45417
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

CVE-2021-32256
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.

CVE-2021-28042
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2021 1 PoC

Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload feature or the MO Connect component. This can lead to remote code execution.

CVE-2021-25761
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.

CVE-2021-0513
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-156090809

CVE-2021-44037
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.

CVE-2021-25407
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-787 2 PoCs

A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.

CVE-2021-44255
Software Genérico General
N/A
UNKNOWN
EPSS
13.6%
2021 1 PoC

Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.

CVE-2021-26310
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.

CVE-2021-28135
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data.

CVE-2021-47536
Linux General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix wrong list_del in smc_lgr_cleanup_early smc_lgr_cleanup_early() meant to delete the link group from the link group list, but it deleted the list head by mistake. This may cause memory corruption since we didn't remove the real link group from the list and later memseted the link group structure. We got a list corruption panic when testing: [  231.277259] list_del corruption. prev->next should be ffff8881398a8000, but was 0000000000000000 [  231.278222] ------------[ cut here ]------------ [  231.278726] kernel

CVE-2021-31915
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.

CVE-2021-26707
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.

CVE-2021-46388
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-45856
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

Accu-Time Systems MAXIMUS 1.0 telnet service suffers from a remote buffer overflow which causes the telnet service to crash

CVE-2021-44428
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2021 1 PoC

Pinkie 2.15 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcode 1.