Show filters
80 Total Results
Displaying 31-40 of 80
Sort by:
Attacker Value
Unknown
CVE-2021-33617
Disclosure Date: July 31, 2021 (last updated November 28, 2024)
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.
0
Attacker Value
Unknown
CVE-2021-32462
Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations. Authentication is required to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2021-32461
Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which could allow a local attacker to trigger a buffer overflow and escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2021-31857
Disclosure Date: June 16, 2021 (last updated November 28, 2024)
In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.
0
Attacker Value
Unknown
CVE-2020-27020
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).
0
Attacker Value
Unknown
CVE-2021-28647
Disclosure Date: April 13, 2021 (last updated February 22, 2025)
Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious DLL file during the installation progress and could execute a malicious program each time a user installs a program.
0
Attacker Value
Unknown
CVE-2020-29392
Disclosure Date: November 30, 2020 (last updated February 22, 2025)
The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical access can unlock the password manager without knowing the master password set by the user.
0
Attacker Value
Unknown
CVE-2020-7962
Disclosure Date: November 13, 2020 (last updated February 22, 2025)
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.
0
Attacker Value
Unknown
CVE-2020-9347
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products
0
Attacker Value
Unknown
CVE-2020-9346
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
0