Show filters
424 Total Results
Displaying 201-210 of 424
Sort by:
Attacker Value
Unknown

CVE-2024-25655

Disclosure Date: March 18, 2024 (last updated February 26, 2025)
Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.
0
Attacker Value
Unknown

CVE-2024-28069

Disclosure Date: March 16, 2024 (last updated February 26, 2025)
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive information and potentially conduct unauthorized actions within the vulnerable component.
0
Attacker Value
Unknown

CVE-2024-23290

Disclosure Date: March 08, 2024 (last updated February 26, 2025)
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to access user-sensitive data.
Attacker Value
Unknown

CVE-2024-23241

Disclosure Date: March 08, 2024 (last updated February 26, 2025)
This issue was addressed through improved state management. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to leak sensitive user information.
Attacker Value
Unknown

CVE-2024-23205

Disclosure Date: March 08, 2024 (last updated February 26, 2025)
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4. An app may be able to access sensitive user data.
Attacker Value
Unknown

CVE-2024-1936

Disclosure Date: March 04, 2024 (last updated February 26, 2025)
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird < 115.8.1.
0
Attacker Value
Unknown

CVE-2023-41829

Disclosure Date: March 04, 2024 (last updated February 26, 2025)
An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.
0
Attacker Value
Unknown

CVE-2023-41827

Disclosure Date: March 04, 2024 (last updated February 26, 2025)
An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.
0
Attacker Value
Unknown

CVE-2024-21826

Disclosure Date: March 04, 2024 (last updated February 26, 2025)
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.
Attacker Value
Unknown

CVE-2024-26131

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start any internal activity by passing some extra parameters. Possible impact includes making Element Android display an arbitrary web page, executing arbitrary JavaScript; bypassing PIN code protection; and account takeover by spawning a login screen to send credentials to an arbitrary home server. This issue is fixed in Element Android 1.6.12. There is no known workaround to mitigate the issue.