Show filters
288 Total Results
Displaying 111-120 of 288
Sort by:
Attacker Value
Unknown
CVE-2019-25056
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mechanism.
0
Attacker Value
Unknown
CVE-2022-23304
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
0
Attacker Value
Unknown
CVE-2022-23303
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
0
Attacker Value
Unknown
CVE-2022-23106
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.
0
Attacker Value
Unknown
CVE-2022-22120
Disclosure Date: January 09, 2022 (last updated February 23, 2025)
In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows attackers to enumerate the registered users' email addresses.
0
Attacker Value
Unknown
CVE-2021-20147
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
0
Attacker Value
Unknown
CVE-2020-35398
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.
0
Attacker Value
Unknown
CVE-2021-20049
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.
0
Attacker Value
Unknown
CVE-2021-38009
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2021-44876
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the identification of the correct tenant for a given user, where a difference in messages could allow an attacker to determine if the given user is valid or not, enabling a brute force attack with valid users.
0