3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-26346
Ryzen 5000 Series General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

CVE-2021-1450
Cisco AnyConnect Secure Mobility Client Networking
5.5
MEDIUM
EPSS
0.1%
2021 CWE-20 1 PoC

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending one or more crafted IPC messages to the AnyConnect process on an affected device. A successful exploit could allow the attacker to stop the AnyConnect p

CVE-2021-3996
util-linux General
5.5
MEDIUM
EPSS
0.2%
2021 CWE-552 1 PoC

A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this flaw to cause a denial of service to applications that use the affected filesystems.

CVE-2021-1122
NVIDIA Virtual GPU Software General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-476 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service.

CVE-2021-4298
Sipity Database
5.5
MEDIUM
EPSS
0.3%
2021 CWE-89 1 PoC

A vulnerability classified as critical has been found in Hesburgh Libraries of Notre Dame Sipity. This affects the function SearchCriteriaForWorksParameter of the file app/parameters/sipity/parameters/search_criteria_for_works_parameter.rb. The manipulation leads to sql injection. Upgrading to version 2021.8 is able to address this issue. The patch is named d1704c7363b899ffce65be03a796a0ee5fdbfbdc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217179.

CVE-2021-35604
MySQL Server Database
5.5
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability im

CVE-2021-28507
EOS General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-284 1 PoC

An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.

CVE-2021-1258
Cisco AnyConnect Secure Mobility Client Networking
5.5
MEDIUM
EPSS
0.0%
2021 CWE-264 2 PoCs

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability by sending a crafted command from the local CLI to the application. A successful exploit could allow the attacker to read arbitrary files on the underlying OS of the affected device. The attacker would need to have valid user credentials to exploit

CVE-2021-31184
Windows 10 Version 1803 Windows
5.5
MEDIUM
EPSS
2.4%
2021 1 PoC

Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability

CVE-2021-31955
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.1%
2021 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2021-25352
Bixby Voice General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-285 2 PoCs

Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.

CVE-2021-27562
🔥 KEV Software Genérico General
5.5
MEDIUM
EPSS
44.5%
2021 1 PoC

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

CVE-2021-1121
NVIDIA Virtual GPU Software General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-770 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource starvation among other vGPUs hosted on the same GPU, which may lead to denial of service.

CVE-2021-43224
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
12.7%
2021 1 PoC

Windows Common Log File System Driver Information Disclosure Vulnerability

CVE-2021-33910
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2021 2 PoCs

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

CVE-2021-34600
CompasX General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-335 2 PoCs

Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.

CVE-2021-23886
McAfee Data Loss Prevention (DLP) Endpoint for Windows Windows
5.5
MEDIUM
EPSS
0.0%
2021 CWE-755 2 PoCs

Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory.

CVE-2021-1095
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.

CVE-2021-1102
NVIDIA Virtual GPU Software General
5.5
MEDIUM
EPSS
0.0%
2021 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can lead to floating point exceptions, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-26354
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
5.5
MEDIUM
EPSS
0.1%
2021 2 PoCs

Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.