Show filters
371 Total Results
Displaying 61-70 of 371
Sort by:
Attacker Value
Unknown
CVE-2021-20146
Disclosure Date: December 09, 2021 (last updated February 23, 2025)
An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.
0
Attacker Value
Unknown
CVE-2021-43978
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.
0
Attacker Value
Unknown
CVE-2020-27413
Disclosure Date: December 07, 2021 (last updated February 23, 2025)
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.
0
Attacker Value
Unknown
CVE-2021-42306
Disclosure Date: November 24, 2021 (last updated February 23, 2025)
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application.
Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application.
Microsoft has identified services that could manifest this vulnerability, and steps that customers should take to be protected. Refer to the FAQ section for more information.
For more details on this issue, please refer to the MSRC Blog Entry.
0
Attacker Value
Unknown
CVE-2021-3789
Disclosure Date: November 12, 2021 (last updated February 23, 2025)
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages.
0
Attacker Value
Unknown
CVE-2021-43332
Disclosure Date: November 12, 2021 (last updated February 23, 2025)
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.
0
Attacker Value
Unknown
CVE-2021-41972
Disclosure Date: November 12, 2021 (last updated February 23, 2025)
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.
0
Attacker Value
Unknown
CVE-2021-38976
Disclosure Date: November 12, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781.
0
Attacker Value
Unknown
CVE-2021-43397
Disclosure Date: November 11, 2021 (last updated February 23, 2025)
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.
0
Attacker Value
Unknown
CVE-2021-40503
Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the attacker would be able to logon to the backend system the SAP GUI for Windows was connected to and launch further attacks depending on the authorizations of the user.
0