Show filters
667 Total Results
Displaying 31-40 of 667
Sort by:
Attacker Value
Unknown

CVE-2021-3461

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
Attacker Value
Unknown

CVE-2021-30332

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Attacker Value
Unknown

CVE-2021-30329

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Attacker Value
Unknown

CVE-2021-30328

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
Attacker Value
Unknown

CVE-2021-43142

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.
Attacker Value
Unknown

CVE-2021-33208

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.
Attacker Value
Unknown

CVE-2021-39787

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-202506934
Attacker Value
Unknown

CVE-2021-39765

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201535427
Attacker Value
Unknown

CVE-2022-1018

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
Attacker Value
Unknown

CVE-2022-28155

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.