Show filters
86 Total Results
Displaying 1-10 of 86
Sort by:
Attacker Value
High

CVE-2020-9337

Disclosure Date: February 26, 2020 (last updated February 21, 2025)
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
Attacker Value
Unknown

CVE-2017-16632

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
In SapphireIMS 4097_1, the password in the database is stored in Base64 format.
Attacker Value
Unknown

CVE-2021-28094

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32.
Attacker Value
Unknown

CVE-2021-28095

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.
Attacker Value
Unknown

CVE-2021-37606

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attacker to infer collisions by measuring timing differences.
Attacker Value
Unknown

CVE-2021-28093

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.
Attacker Value
Unknown

CVE-2021-20360

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195031.
Attacker Value
Unknown

CVE-2021-20369

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195361.
Attacker Value
Unknown

CVE-2021-34430

Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.
Attacker Value
Unknown

CVE-2021-32496

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concerning the internal SSH interface solely used by SICK for recovering returned devices. The use of weak ciphers make it easier for an attacker to break the security that protects information transmitted from the client to the SSH server, assuming the attacker has access to the network on which the device is connected. This can increase the risk that encryption will be compromised, leading to the exposure of sensitive user information and man-in-the-middle attacks.