Show filters
174 Total Results
Displaying 101-110 of 174
Sort by:
Attacker Value
Unknown

CVE-2021-22419

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos.
Attacker Value
Unknown

CVE-2021-36367

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
Attacker Value
Unknown

CVE-2021-21588

Disclosure Date: July 01, 2021 (last updated February 23, 2025)
Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and perform which may lead to configuration changes.
Attacker Value
Unknown

CVE-2021-29963

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.
Attacker Value
Unknown

CVE-2021-23998

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Attacker Value
Unknown

CVE-2021-33887

Disclosure Date: June 15, 2021 (last updated February 22, 2025)
Insufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physical access to boot into a modified kernel/ramdisk without unlocking the bootloader.
Attacker Value
Unknown

CVE-2021-33712

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
A vulnerability has been identified in Mendix SAML Module (All versions < V2.1.2). The configuration of the SAML module does not properly check various restrictions and validations imposed by an identity provider. This could allow a remote authenticated attacker to escalate privileges.
Attacker Value
Unknown

CVE-2021-33840

Disclosure Date: June 04, 2021 (last updated February 22, 2025)
The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digital signature.
Attacker Value
Unknown

CVE-2021-32665

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
wire-ios is the iOS version of Wire, an open-source secure messaging app. wire-ios versions 3.8.0 and earlier have a bug in which a conversation could be incorrectly set to "unverified. This occurs when: - Self user is added to a new conversation - Self user is added to an existing conversation - All the participants in the conversation were previously marked as verified. The vulnerability is patched in wire-ios version 3.8.1. As a workaround, one can unverify & verify a device in the conversation.
Attacker Value
Unknown

CVE-2021-28678

Disclosure Date: June 02, 2021 (last updated February 22, 2025)
An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data.