7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47126
Linux Web
5.5
MEDIUM
EPSS
0.0%
2021 1 PoC

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions Reported by syzbot: HEAD commit: 90c911ad Merge tag 'fixes' of git://git.kernel.org/pub/scm.. git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master dashboard link: https://syzkaller.appspot.com/bug?extid=123aa35098fd3c000eb7 compiler: Debian clang version 11.0.1-2 ================================================================== BUG: KASAN: slab-out-of-bounds in fib6_nh_get_excptn_bucket net/ipv6/route.c:1604 [in

CVE-2021-25456
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.

CVE-2021-46791
3rd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted SMM executable binary to corrupt Dynamic Root of Trust for Measurement (DRTM) user application memory that may result in a potential denial of service.

CVE-2021-26404
3rd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

CVE-2021-27414
Ellipse Enterprise Asset Management (EAM) General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-451 1 PoC

An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials.

CVE-2021-3863
snipe/snipe-it Web
5.5
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-22207
Wireshark General
5.5
MEDIUM
EPSS
0.5%
2021 1 PoC

Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file

CVE-2021-31970
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.8%
2021 1 PoC

Windows TCP/IP Driver Security Feature Bypass Vulnerability

CVE-2021-47114
Linux General
5.5
MEDIUM
EPSS
0.0%
2021 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption by fallocate When fallocate punches holes out of inode size, if original isize is in the middle of last cluster, then the part from isize to the end of the cluster will be zeroed with buffer write, at that time isize is not yet updated to match the new size, if writeback is kicked in, it will invoke ocfs2_writepage()->block_write_full_page() where the pages out of inode size will be dropped. That will cause file corruption. Fix this by zero out eof blocks when extending the inode size. Running t

CVE-2021-34496
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
2.4%
2021 1 PoC

Windows GDI Information Disclosure Vulnerability

CVE-2021-26407
2nd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information disclosure.

CVE-2021-25381
Samsung Account General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-285 2 PoCs

Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

CVE-2021-25349
Slow Motion Editor General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-284 2 PoCs

Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent.

CVE-2021-25352
Bixby Voice General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-285 2 PoCs

Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.

CVE-2021-34564
WHA-GW-F2D2-0-AS- Z2-ETH Networking
5.5
MEDIUM
EPSS
0.0%
2021 CWE-315 1 PoC

Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.

CVE-2021-1096
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where dereferencing a NULL pointer may lead to a system crash.

CVE-2021-27562
🔥 KEV Software Genérico General
5.5
MEDIUM
EPSS
44.5%
2021 1 PoC

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

CVE-2021-24084
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.0%
2021 2 PoCs

Windows Mobile Device Management Information Disclosure Vulnerability

CVE-2021-26371
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
5.5
MEDIUM
EPSS
0.1%
2021 2 PoCs

A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.

CVE-2021-33910
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2021 2 PoCs

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.