VYPR

CVEs

101,988 total · page 1214 of 2,040

  • CVE-2021-44828HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Arm Mali GPU Kernel Driver (Midgard r26p0 through r30p0, Bifrost r0p0 through r34p0, and Valhall r19p0 through r34p0) allows a non-privileged user to achieve write access to read-only memory, and possibly obtain root privileges, corrupt memory, and modify the memory of other…

  • CVE-2021-44743HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2021-44711HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.10

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this…

  • CVE-2021-44710HigJan 14, 2022
    risk 0.52cvss 7.8epss 0.12

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current…

  • CVE-2021-44709HigJan 14, 2022
    risk 0.53cvss 7.8epss 0.30

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the…

  • CVE-2021-44708HigJan 14, 2022
    risk 0.54cvss 7.8epss 0.39

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the…

  • CVE-2021-44707HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.08

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2021-44706HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.09

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current…

  • CVE-2021-44705HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.07

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current…

  • CVE-2021-44704HigJan 14, 2022
    risk 0.52cvss 7.8epss 0.11

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current…

  • CVE-2021-44703HigJan 14, 2022
    risk 0.55cvss 7.8epss 0.57

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of…

  • CVE-2021-44701HigJan 14, 2022
    risk 0.52cvss 7.8epss 0.21

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current…

  • CVE-2021-3965HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.05

    Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.

  • CVE-2021-39684HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In target_init of gs101/abl/target/slider/target.c, there is a possible allocation of RWX memory due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-39682HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In mgm_alloc_page of memory_group_manager.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39681HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In delete_protocol of main.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-39679HigJan 14, 2022
    risk 0.46cvss 7.0epss 0.00

    In init of vendor_graphicbuffer_meta.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39678HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In of , there is a possible bypass of Factory Reset Protection due to . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2021-39634HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In fs/eventpoll.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204450605References:…

  • CVE-2021-39632HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39630HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-39629HigJan 14, 2022
    risk 0.46cvss 7.0epss 0.00

    In phTmlNfc_Init and phTmlNfc_CleanUp of phTmlNfc.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39627HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…

  • CVE-2021-39626HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-39625HigJan 14, 2022
    risk 0.47cvss 7.3epss 0.00

    In showCarrierAppInstallationNotification of EuiccNotificationManager.java, there is a possible way to gain an access to MediaProvider content due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction…

  • CVE-2021-39622HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39621HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…

  • CVE-2021-39620HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39618HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In multiple methods of EuiccNotificationManager.java, there is a possible way to install existing packages without user consent due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed…

  • CVE-2021-23567HigJan 14, 2022
    risk 0.42cvss 7.5epss 0.02

    The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in the americanFlag module. Unfortunately this appears to have been a purposeful attempt by a maintainer of colors to make the package unusable, other…

  • CVE-2021-23157HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.08

    WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.

  • CVE-2021-23138HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.09

    WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.

  • CVE-2021-20613HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.04

    Improper initialization vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware version 1.16 and prior and FX3U-ENET-P502 Firmware version 1.16 and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS)…

  • CVE-2021-20612HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.04

    Lack of administrator control over security vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.14 and prior, FX3U-ENET-L Firmware version 1.14 and prior and FX3U-ENET-P502 Firmware version 1.14 and prior allows a remote unauthenticated attacker to cause a…

  • CVE-2021-1036HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-1035HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In setLaunchIntent of BluetoothDevicePickerPreferenceController.java, there is a possible way to invoke an arbitrary broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2021-0959HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In jit_memory_region.cc, there is a possible bypass of memory restrictions due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-45761HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.01

    ROPium v3.1 was discovered to contain an invalid memory address dereference via the find() function.

  • CVE-2022-21681HigJan 14, 2022
    risk 0.42cvss 7.5epss 0.03

    Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who runs untrusted markdown through a vulnerable version of…

  • CVE-2022-21680HigJan 14, 2022
    risk 0.42cvss 7.5epss 0.03

    Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable…

  • CVE-2021-32650HigJan 14, 2022
    risk 0.50cvss 8.8epss 0.02

    October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backend is able to execute PHP code by using the theme import feature. This will bypass the safe mode…

  • CVE-2021-32649HigJan 14, 2022
    risk 0.50cvss 8.8epss 0.01

    October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the backend is able to execute PHP code by running specially…

  • CVE-2022-23222HigJan 14, 2022
    risk 0.00cvss 7.8epss 0.02

    kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.

  • CVE-2022-20698HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to…

  • CVE-2021-46255HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.

  • CVE-2021-38692HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…

  • CVE-2021-38691HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…

  • CVE-2021-38690HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…

  • CVE-2021-38689HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…

  • CVE-2021-38682HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR…