Show filters
176 Total Results
Displaying 1-10 of 176
Sort by:
Attacker Value
Unknown

CVE-2021-38373

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
Attacker Value
Unknown

CVE-2021-22923

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and without telling the user it happened.
Attacker Value
Unknown

CVE-2021-33900

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.
Attacker Value
Unknown

CVE-2021-29769

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 202769.
Attacker Value
Unknown

CVE-2020-36423

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
Attacker Value
Unknown

CVE-2020-12730

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
Attacker Value
Unknown

CVE-2020-4980

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
Attacker Value
Unknown

CVE-2021-1896

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
Weak configuration in WLAN could cause forwarding of unencrypted packets from one client to another in Snapdragon Compute, Snapdragon Connectivity
Attacker Value
Unknown

CVE-2021-36382

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
Attacker Value
Unknown

CVE-2021-22380

Disclosure Date: June 30, 2021 (last updated February 22, 2025)
There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality and availability.