CVE-2021-33625
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function
CVSS
7.5
Alto
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 3 feb 2022 · Última mod.: 11 ago 2026 · CWE-119
0.3%EPSS · 30 días0.3%
2026-08-142026-09-11
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20220222-0004/
- www.insyde.comhttps://www.insyde.com/security-pledge
- www.insyde.comhttps://www.insyde.com/security-pledge/SA-2022014
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20220222-0004/
- www.insyde.comhttps://www.insyde.com/security-pledge
- www.insyde.comhttps://www.insyde.com/security-pledge/SA-2022014
- www.kb.cert.orghttps://www.kb.cert.org/vuls/id/796611
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/html/ssa-306654.html
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-879337.3 ALT23.2%
——7A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.2dCVE-2026-879319.6 CRÍ37.7%
——11A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.2dCVE-2026-874898.8 ALT14.1%
——4Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)2dCVE-2026-874448.8 ALT37.3%
——11Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-867167.3 ALT27.7%
——8A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.4dCVE-2026-796028.8 ALT3.0%
——1A guest with a PCI device assigned that has at least a BAR on the IO port
space can trigger a BUG() in Xen.2d