Show filters
440 Total Results
Displaying 281-290 of 440
Sort by:
Attacker Value
Unknown

CVE-2020-36421

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.
Attacker Value
Unknown

CVE-2020-36423

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
Attacker Value
Unknown

CVE-2020-36424

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.
Attacker Value
Unknown

CVE-2020-36425

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
Attacker Value
Unknown

CVE-2020-36422

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.
Attacker Value
Unknown

CVE-2021-24119

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
Attacker Value
Unknown

CVE-2021-26274

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
The Agent in NinjaRMM 5.0.909 has Insecure Permissions.
Attacker Value
Unknown

CVE-2021-26273

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.
Attacker Value
Unknown

CVE-2021-26314

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
Attacker Value
Unknown

CVE-2021-26313

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.