Show filters
1,081 Total Results
Displaying 241-250 of 1,081
Sort by:
Attacker Value
Unknown

CVE-2020-3940

Disclosure Date: January 17, 2020 (last updated February 21, 2025)
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
Attacker Value
Unknown

CVE-2020-5499

Disclosure Date: January 04, 2020 (last updated November 27, 2024)
Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.
Attacker Value
Unknown

CVE-2014-0161

Disclosure Date: January 02, 2020 (last updated February 21, 2025)
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote endpoints via an arbitrary valid certificate.
Attacker Value
Unknown

CVE-2019-14565

Disclosure Date: November 14, 2019 (last updated November 08, 2023)
Insufficient initialization in Intel(R) SGX SDK Windows versions 2.4.100.51291 and earlier, and Linux versions 2.6.100.51363 and earlier, may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.
Attacker Value
Unknown

CVE-2019-14566

Disclosure Date: November 14, 2019 (last updated November 08, 2023)
Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.
Attacker Value
Unknown

CVE-2019-15301

Disclosure Date: September 18, 2019 (last updated November 08, 2023)
A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.
Attacker Value
Unknown

CVE-2019-12586

Disclosure Date: September 04, 2019 (last updated November 27, 2024)
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.
0
Attacker Value
Unknown

CVE-2019-12587

Disclosure Date: September 04, 2019 (last updated November 27, 2024)
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows the installation of a zero Pairwise Master Key (PMK) after the completion of any EAP authentication method, which allows attackers in radio range to replay, decrypt, or spoof frames via a rogue access point.
0
Attacker Value
Unknown

CVE-2019-12588

Disclosure Date: September 04, 2019 (last updated November 27, 2024)
The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count in beacon frames, probe responses, and association responses, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.
Attacker Value
Unknown

CVE-2019-15786

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket.
0