7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25392
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-200 2 PoCs

Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.

CVE-2021-25364
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-200 2 PoCs

A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.

CVE-2021-3448
dnsmasq General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-358 1 PoC

A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a reply and get it accepted by dnsmasq. This flaw makes a DNS Cache Poisoning attack much easier. The highest threat from this vulnerability is to data integrity.

CVE-2021-25515
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-269 1 PoC

An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.

CVE-2021-2152
Business Intelligence Enterprise Edition Web Database
4.0
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional

CVE-2021-46676
Pandora FMS Web
4.0
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field.

CVE-2021-25359
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-284 2 PoCs

An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.

CVE-2021-23883
Endpoint Security (ENS) for Windows Windows
4.0
MEDIUM
EPSS
0.1%
2021 CWE-476 1 PoC

A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. This varies by machine and had partial protection prior to this update.

CVE-2021-25463
PENUP General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-284 1 PoC

Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.

CVE-2021-25343
Samsung Members General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-287 2 PoCs

Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-25358
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-256 2 PoCs

A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.

CVE-2021-25461
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-120 2 PoCs

An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.

CVE-2021-25483
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.

CVE-2021-25523
SamsungDialer General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-922 1 PoC

Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.

CVE-2021-25342
SMP sdk General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-287 2 PoCs

Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-25494
Samsung Notes General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

A possible buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.

CVE-2021-25472
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-264 1 PoC

An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.

CVE-2021-25345
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 2 PoCs

Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format.

CVE-2021-25391
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-926 2 PoCs

Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

CVE-2021-46680
Pandora FMS Web
4.0
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field.