Show filters
176 Total Results
Displaying 1-10 of 176
Sort by:
Attacker Value
Unknown
CVE-2021-38373
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
0
Attacker Value
Unknown
CVE-2021-22923
Disclosure Date: August 05, 2021 (last updated February 23, 2025)
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.
0
Attacker Value
Unknown
CVE-2021-33900
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.
0
Attacker Value
Unknown
CVE-2021-29769
Disclosure Date: July 23, 2021 (last updated February 23, 2025)
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 202769.
0
Attacker Value
Unknown
CVE-2020-36423
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
0
Attacker Value
Unknown
CVE-2020-12730
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
0
Attacker Value
Unknown
CVE-2020-4980
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
0
Attacker Value
Unknown
CVE-2021-1896
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
Weak configuration in WLAN could cause forwarding of unencrypted packets from one client to another in Snapdragon Compute, Snapdragon Connectivity
0
Attacker Value
Unknown
CVE-2021-36382
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
0
Attacker Value
Unknown
CVE-2021-22380
Disclosure Date: June 30, 2021 (last updated February 22, 2025)
There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality and availability.
0