|
196141
|
8.4 |
HIGH
Local
|
amd
|
epyc_7001_firmware epyc_7232p_firmware epyc_7251_firmware epyc_7261_firmware epyc_7252_firmware epyc_74f3_firmware epyc_7501_firmware epyc_7502_firmware epyc_7502p_firmware
|
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior ins…
|
NVD-CWE-noinfo
|
CVE-2021-26340
|
2024-11-21 14:56 |
2021-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196142
|
9.8 |
CRITICAL
Network
|
circutor
|
compact_dc-s_basic_firmware
|
Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to execute arbitrary c…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-26777
|
2024-11-21 14:56 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196143
|
9.9 |
CRITICAL
Network
|
amd
|
amd_uprof
|
The AMDPowerProfiler.sys driver of AMD µProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged us…
|
NVD-CWE-Other
|
CVE-2021-26334
|
2024-11-21 14:56 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196144
|
9.8 |
CRITICAL
Network
|
tobesoft
|
nexacro
|
An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creatio…
|
CWE-20
Improper Input Validation
|
CVE-2021-26612
|
2024-11-21 14:56 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196145
|
8.8 |
HIGH
Network
|
bandisoft
|
ark_library
|
ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-26615
|
2024-11-21 14:56 |
2021-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196146
|
9.8 |
CRITICAL
Network
|
hej
|
hejhome_gkw-ic052_firmware
|
HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..)
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-26611
|
2024-11-21 14:56 |
2021-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196147
|
9.8 |
CRITICAL
Network
|
iptime
|
c200_firmware
|
ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell comma…
|
NVD-CWE-noinfo
|
CVE-2021-26614
|
2024-11-21 14:56 |
2021-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196148
|
5.5 |
MEDIUM
Local
|
philips
|
mri_3t_firmware mri_1.5t_firmware
|
Philips MRI 1.5T and MRI 3T Version 5.x.x does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
|
NVD-CWE-Other
|
CVE-2021-26262
|
2024-11-21 14:56 |
2021-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196149
|
5.5 |
MEDIUM
Local
|
amd
|
epyc_7003_firmware epyc_7002_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware …
|
Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.
|
NVD-CWE-noinfo
|
CVE-2021-26337
|
2024-11-21 14:56 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196150
|
5.5 |
MEDIUM
Local
|
amd
|
epyc_7003_firmware epyc_7002_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware …
|
Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-26336
|
2024-11-21 14:56 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|