Show filters
43 Total Results
Displaying 21-30 of 43
Sort by:
Attacker Value
Unknown
CVE-2021-23999
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
0
Attacker Value
Unknown
CVE-2020-1920
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.
0
Attacker Value
Unknown
CVE-2020-22784
Disclosure Date: April 28, 2021 (last updated February 22, 2025)
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
0
Attacker Value
Unknown
CVE-2020-25580
Disclosure Date: March 26, 2021 (last updated February 22, 2025)
In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a regression in the login.access(5) rule processor has the effect of causing rules to fail to match even when they should not. This means that rules denying access may be ignored.
0
Attacker Value
Unknown
CVE-2021-20219
Disclosure Date: March 23, 2021 (last updated February 22, 2025)
A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity check) and cause a threat to the system availability.
0
Attacker Value
Unknown
CVE-2020-23360
Disclosure Date: January 27, 2021 (last updated February 22, 2025)
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
0
Attacker Value
Unknown
CVE-2020-23359
Disclosure Date: January 27, 2021 (last updated February 22, 2025)
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can still bypass the check.
0
Attacker Value
Unknown
CVE-2020-13559
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A specially crafted packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-3116
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
before_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authorization header data because of a boolean confusion (and versus or).
0
Attacker Value
Unknown
CVE-2019-20925
Disclosure Date: November 24, 2020 (last updated February 22, 2025)
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.
0