Show filters
112 Total Results
Displaying 1-10 of 112
Sort by:
Attacker Value
Unknown
CVE-2021-37704
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public access.
0
Attacker Value
Unknown
CVE-2021-22385
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
0
Attacker Value
Unknown
CVE-2020-21356
Disclosure Date: August 06, 2021 (last updated February 23, 2025)
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.
0
Attacker Value
Unknown
CVE-2021-22420
Disclosure Date: August 03, 2021 (last updated February 23, 2025)
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
0
Attacker Value
Unknown
CVE-2021-32788
Disclosure Date: July 27, 2021 (last updated February 23, 2025)
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic.
0
Attacker Value
Unknown
CVE-2021-32760
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in containerd 1.5.4 and 1.4.8. As a workaround, ensure that users only pull images from trusted sources. Linux security modules (LSMs) like SELinux and AppArmor can limit the files potentially affected by this bug through policies and profiles that prevent containerd from interacting with specific files.
0
Attacker Value
Unknown
CVE-2021-0588
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-177238342
0
Attacker Value
Unknown
CVE-2020-22535
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.
0
Attacker Value
Unknown
CVE-2021-25432
Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data.
0
Attacker Value
Unknown
CVE-2020-27361
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.
0