3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-27290
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2021 2 PoCs

ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

CVE-2021-45421
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or replaced

CVE-2021-46744
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.

CVE-2021-32098
Software Genérico General
N/A
UNKNOWN
EPSS
2.8%
2021 1 PoC

Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.

CVE-2021-37162
Software Genérico General
N/A
UNKNOWN
EPSS
7.6%
2021 1 PoC

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. If an attacker sends a malformed UDP message, a buffer underflow occurs, leading to an out-of-bounds copy and possible remote code execution.

CVE-2021-42631
Software Genérico General
N/A
UNKNOWN
EPSS
20.6%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.

CVE-2021-25330
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-42008
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 5 PoCs

The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.

CVE-2021-46452
Software Genérico General
N/A
UNKNOWN
EPSS
4.3%
2021 1 PoC

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via the tomography_ping_address, tomography_ping_number, tomography_ping_size, tomography_ping_timeout, and tomography_ping_ttl parameters.

CVE-2021-35391
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL.

CVE-2021-34170
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2021 1 PoC

Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.

CVE-2021-43546
Thunderbird General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVE-2021-0317
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Android-11, Android-8.0, Android-8.1, Android-9; Android ID: A-168319670.

CVE-2021-28964
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.

CVE-2021-38137
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, allowing a user to perform actions not belonging to his role.

CVE-2021-27187
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is checked.

CVE-2021-31610
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (either restart or deadlock the device) by flooding a device with LMP_AU_rand data.

CVE-2021-34149
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.

CVE-2021-33259
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

CVE-2021-26317
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.