Show filters
755 Total Results
Displaying 31-40 of 755
Sort by:
Attacker Value
Unknown

CVE-2021-45038

Disclosure Date: December 17, 2021 (last updated February 23, 2025)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.
Attacker Value
Unknown

CVE-2021-45095

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.
Attacker Value
Unknown

CVE-2021-1023

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195963373
Attacker Value
Unknown

CVE-2021-0983

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about installed device/profile owner package name due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-192245204
Attacker Value
Unknown

CVE-2021-43823

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in private source code could be guessed by an authenticated but unauthorized actor. This issue affects the Saved Searches and Code Monitoring features. A successful attack would require an authenticated bad actor to create many Saved Searches or Code Monitors to receive confirmation that a specific string exists. This could allow an attacker to guess formatted tokens in source code, such as API keys. This issue was patched in version 3.33.2 and any future versions of Sourcegraph. We strongly encourage upgrading to secure versions. If you are unable to, you may disable Saved Searches and Code Monitors.
0
Attacker Value
Unknown

CVE-2021-39941

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members
Attacker Value
Unknown

CVE-2021-24945

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
Attacker Value
Unknown

CVE-2018-25022

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Onion module in toxcore before 0.2.2 doesn't restrict which packets can be onion-routed, which allows a remote attacker to discover a target user's IP address (when knowing only their Tox Id) by positioning themselves close to target's Tox Id in the DHT for the target to establish an onion connection with the attacker, guessing the target's DHT public key and creating a DHT node with public key close to it, and finally onion-routing a NAT Ping Request to the target, requesting it to ping the just created DHT node.
Attacker Value
Unknown

CVE-2021-37935

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.
Attacker Value
Unknown

CVE-2021-38901

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Force ID: 209610.