Show filters
174 Total Results
Displaying 31-40 of 174
Sort by:
Attacker Value
Unknown
CVE-2021-26318
Disclosure Date: October 12, 2021 (last updated February 23, 2025)
A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information.
0
Attacker Value
Unknown
CVE-2021-24651
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.
0
Attacker Value
Unknown
CVE-2021-37968
Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2021-38476
Disclosure Date: October 07, 2021 (last updated February 23, 2025)
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and validates the existence of a username. This may allow an attacker to enumerate different user accounts.
0
Attacker Value
Unknown
CVE-2021-20376
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to there being an observable discrepancy in returned messages. IBM X-Force ID: 195568.
0
Attacker Value
Unknown
CVE-2021-38153
Disclosure Date: September 22, 2021 (last updated February 23, 2025)
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
0
Attacker Value
Unknown
CVE-2021-39189
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.
0
Attacker Value
Unknown
CVE-2021-37151
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate between a valid user and an invalid one (aka Username Enumeration). Response differentiation enables attackers to enumerate usernames of valid application users. Attackers can use this information to leverage brute-force and dictionary attacks in order to discover valid account information such as passwords.
0
Attacker Value
Unknown
CVE-2021-34576
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists. This may give sensitive information (water consumption without distinct values) to third parties.
0
Attacker Value
Unknown
CVE-2020-25082
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel attack against ECDSA, because of an Observable Timing Discrepancy.
0