Show filters
121 Total Results
Displaying 11-20 of 121
Sort by:
Attacker Value
Unknown

CVE-2021-33880

Disclosure Date: June 06, 2021 (last updated February 22, 2025)
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.
Attacker Value
Unknown

CVE-2021-33838

Disclosure Date: June 04, 2021 (last updated February 22, 2025)
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after requests for Phone Number Registration.
Attacker Value
Unknown

CVE-2021-22892

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.
Attacker Value
Unknown

CVE-2020-27211

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
Attacker Value
Unknown

CVE-2021-29415

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA implemenation. This allows an adversary to recover the private ECC key used during an ECDSA operation.
Attacker Value
Unknown

CVE-2021-29687

Disclosure Date: May 19, 2021 (last updated February 22, 2025)
IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018
Attacker Value
Unknown

CVE-2021-27342

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack
Attacker Value
Unknown

CVE-2021-21424

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that 403s are returned whether the user exists or not if a user cannot switch to a user or if the user does not exist. The patch for this issue is available for branch 3.4.
Attacker Value
Unknown

CVE-2021-1486

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A successful exploit could allow the attacker to compare the HTTP responses that are returned by the affected system to determine which accounts are valid user accounts.
Attacker Value
Unknown

CVE-2021-31866

Disclosure Date: April 28, 2021 (last updated February 22, 2025)
Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController.