Show filters
440 Total Results
Displaying 261-270 of 440
Sort by:
Attacker Value
Unknown
CVE-2022-0437
Disclosure Date: February 05, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
0
Attacker Value
Unknown
CVE-2021-44837
Disclosure Date: January 19, 2022 (last updated February 23, 2025)
An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an admin user regarding the risk creation information in the /risque/administration/referentiel/json/create/categorie endpoint, using the id_cat1 query parameter to indicate the risk.
0
Attacker Value
Unknown
CVE-2021-44839
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).
0
Attacker Value
Unknown
CVE-2021-44838
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating the risk to access with the id parameter, it is possible for users to access risks of other companies.
0
Attacker Value
Unknown
CVE-2021-44836
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the risk to be re-opened.
0
Attacker Value
Unknown
CVE-2021-44840
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk labels, such as Criticality and Priority Indication labels. By using the /core/table/query endpoint, and by using a POST request and indicating the affected label with tableUid parameter and the operation with datas[query], it is possible to edit, create, and delete the following labels: Priority Indication, Quality Evaluation, Progress Margin and Priority. Furthermore, it is also possible to export Criticality labels with an unprivileged user.
0
Attacker Value
Unknown
CVE-2021-44828
Disclosure Date: January 14, 2022 (last updated February 23, 2025)
Arm Mali GPU Kernel Driver (Midgard r26p0 through r30p0, Bifrost r0p0 through r34p0, and Valhall r19p0 through r34p0) allows a non-privileged user to achieve write access to read-only memory, and possibly obtain root privileges, corrupt memory, and modify the memory of other processes.
0
Attacker Value
Unknown
CVE-2021-45451
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
0
Attacker Value
Unknown
CVE-2021-45450
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
0
Attacker Value
Unknown
CVE-2021-44732
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
0