Show filters
253 Total Results
Displaying 81-90 of 253
Sort by:
Attacker Value
Unknown
CVE-2021-20147
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
0
Attacker Value
Unknown
CVE-2020-35398
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers to brute force enumeration of usernames determined by the error message returned after invalid credentials are attempted.
0
Attacker Value
Unknown
CVE-2021-20049
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.
0
Attacker Value
Unknown
CVE-2021-38009
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2021-44876
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the identification of the correct tenant for a given user, where a difference in messages could allow an attacker to determine if the given user is valid or not, enabling a brute force attack with valid users.
0
Attacker Value
Unknown
CVE-2021-44875
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the password recovery procedure for a given user, where a difference in messages could allow an attacker to determine if the given user is valid or not, enabling a brute force attack with valid users.
0
Attacker Value
Unknown
CVE-2021-44554
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message returned; it can be presented in different languages according to the configuration of VirtualUI. Common users are administrator, admin, guest and krgtbt.
0
Attacker Value
Unknown
CVE-2021-1032
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In getMimeGroup of PackageManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-184745603
0
Attacker Value
Unknown
CVE-2021-1031
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In cancelNotificationsFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194697004
0
Attacker Value
Unknown
CVE-2021-1030
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In setNotificationsShownFromListener of NotificationManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194697001
0