Show filters
699 Total Results
Displaying 251-260 of 699
Sort by:
Attacker Value
Unknown
CVE-2021-3505
Disclosure Date: April 19, 2021 (last updated February 22, 2025)
A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.
0
Attacker Value
Unknown
CVE-2021-24225
Disclosure Date: April 12, 2021 (last updated February 22, 2025)
The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue
0
Attacker Value
Unknown
CVE-2021-24150
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).
0
Attacker Value
Unknown
CVE-2021-29251
Disclosure Date: April 01, 2021 (last updated November 28, 2024)
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.
0
Attacker Value
Unknown
CVE-2021-29249
Disclosure Date: March 26, 2021 (last updated November 28, 2024)
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
0
Attacker Value
Unknown
CVE-2021-3446
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps. The highest threat from this vulnerability is to data confidentiality.
0
Attacker Value
Unknown
CVE-2020-35524
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
0
Attacker Value
Unknown
CVE-2020-35522
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack.
0
Attacker Value
Unknown
CVE-2020-35523
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
0
Attacker Value
Unknown
CVE-2020-35521
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.
0