Show filters
667 Total Results
Displaying 31-40 of 667
Sort by:
Attacker Value
Unknown
CVE-2021-3461
Disclosure Date: April 01, 2022 (last updated February 23, 2025)
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
0
Attacker Value
Unknown
CVE-2021-30332
Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
0
Attacker Value
Unknown
CVE-2021-30329
Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
0
Attacker Value
Unknown
CVE-2021-30328
Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
0
Attacker Value
Unknown
CVE-2021-43142
Disclosure Date: March 30, 2022 (last updated February 23, 2025)
An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.
0
Attacker Value
Unknown
CVE-2021-33208
Disclosure Date: March 30, 2022 (last updated February 23, 2025)
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.
0
Attacker Value
Unknown
CVE-2021-39787
Disclosure Date: March 30, 2022 (last updated February 23, 2025)
In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-202506934
0
Attacker Value
Unknown
CVE-2021-39765
Disclosure Date: March 30, 2022 (last updated February 23, 2025)
In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201535427
0
Attacker Value
Unknown
CVE-2022-1018
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
0
Attacker Value
Unknown
CVE-2022-28155
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0