Show filters
40,694 Total Results
Displaying 271-280 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2021-1779
Disclosure Date: April 02, 2021 (last updated November 28, 2024)
A logic error in kext loading was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. An application may be able to execute arbitrary code with system privileges.
1
Attacker Value
Unknown
CVE-2021-1785
Disclosure Date: April 02, 2021 (last updated November 28, 2024)
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.
1
Attacker Value
Unknown
CVE-2021-1789
Disclosure Date: April 02, 2021 (last updated November 08, 2023)
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.
1
Attacker Value
Unknown
SolarWinds Orion Platform Reverse Tabnabbing and Open Redirect — CVE-2021-3109
Disclosure Date: March 26, 2021 (last updated November 28, 2024)
The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context of an administrator account.
1
Attacker Value
Unknown
SolarWinds Orion Platform Stored XSS in Customize view —CVE-2020-35856
Disclosure Date: March 26, 2021 (last updated November 28, 2024)
SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
1
Attacker Value
Unknown
CVE-2020-27269
Disclosure Date: January 19, 2021 (last updated November 28, 2024)
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measures, which allows unauthenticated, physically proximate attackers to replay communication sequences via Bluetooth Low Energy.
1
Attacker Value
Unknown
CVE-2020-27276
Disclosure Date: January 19, 2021 (last updated November 28, 2024)
SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the communicating entities before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the authentication sequence via Bluetooth Low Energy.
1
Attacker Value
Unknown
CVE-2020-13543
Disclosure Date: December 03, 2020 (last updated November 28, 2024)
A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after-free vulnerability which can lead to remote code execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
1
Attacker Value
Unknown
CVE-2020-16006
Disclosure Date: November 03, 2020 (last updated November 08, 2023)
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1
Attacker Value
Unknown
CVE-2020-16011
Disclosure Date: November 03, 2020 (last updated November 28, 2024)
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
1