SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

31 results for “kev-cve-2021-25487” · 1.20 s · cached

Facets · 1 entity types

31 CVE
CVE-2026-44697CVE

CVE-2026-44697

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any p…

CVSS 8.6EPSS 0.5%
Match for kev-cve-2021-25487
CVE-2025-29778CVE

CVE-2025-29778

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with k…

CVSS 8.0EPSS 0.3%
Match for kev-cve-2021-25487
CVE-2026-45446CVE

CVE-2026-45446

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of …

CVSS 4.8EPSS 0.2%openssl
Match for kev-cve-2021-25487
CVE-2026-40527CVE

CVE-2026-40527

radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_pa…

CVSS 7.8EPSS 1.5%radare
Match for kev-cve-2021-25487
CVE-2026-48556CVE

CVE-2026-48556

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2021-25487
CVE-2026-45497CVE

CVE-2026-45497

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

CVSS 7.7EPSS 0.6%microsoft
Match for kev-cve-2021-25487
CVE-2026-5434CVE

CVE-2026-5434

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially…

CVSS 5.9EPSS 0.3%
Match for kev-cve-2021-25487
CVE-2024-56121CVE

CVE-2024-56121

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2021-25487
CVE-2026-45447CVE

CVE-2026-45447

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes…

CVSS 8.8EPSS 4.0%openssl
Match for kev-cve-2021-25487
CVE-2026-5433CVE

CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Rem…

CVSS 9.1EPSS 1.6%
Match for kev-cve-2021-25487
CVE-2024-56122CVE

CVE-2024-56122

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2021-25487
CVE-2021-25487CVE

Samsung Mobile Devices Out-of-Bounds Read Vulnerability

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution…

EPSS 0.6%KEVSamsung
Match for kev-cve-2021-25487
CVE-2026-45474CVE

CVE-2026-45474

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS 8.4EPSS 0.4%microsoft
Match for kev-cve-2021-25487
CVE-2026-45472CVE

CVE-2026-45472

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS 8.4EPSS 0.4%microsoft
Match for kev-cve-2021-25487
CVE-2026-45475CVE

CVE-2026-45475

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS 7.8EPSS 0.6%microsoft
Match for kev-cve-2021-25487
CVE-2026-35433CVE

CVE-2026-35433

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

CVSS 7.3EPSS 0.6%microsoft
Match for kev-cve-2021-25487
CVE-2026-45463CVE

CVE-2026-45463

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS 8.4EPSS 0.4%microsoft
Match for kev-cve-2021-25487
CVE-2026-40687CVE

CVE-2026-40687

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data process…

CVSS 9.1EPSS 0.7%
Match for kev-cve-2021-25487
CVE-2026-40685CVE

CVE-2026-40685

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2021-25487
CVE-2026-45461CVE

CVE-2026-45461

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS 8.4EPSS 0.4%microsoft
Match for kev-cve-2021-25487
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.