Show filters
89 Total Results
Displaying 41-50 of 89
Sort by:
Attacker Value
Unknown

CVE-2022-0070

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
Attacker Value
Unknown

CVE-2021-3100

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
Attacker Value
Unknown

CVE-2021-44161

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.
0
Attacker Value
Unknown

CVE-2021-42111

Disclosure Date: November 10, 2021 (last updated October 07, 2023)
An issue was discovered in the RCDevs OpenOTP app 1.4.13 and 1.4.14 for iOS. If it is installed on a jailbroken device, it is possible to retrieve the PIN code used to access the application. The IOS app version 1.4.1631262629 resolves this issue by storing a hash PIN code.
Attacker Value
Unknown

CVE-2021-29221

Disclosure Date: April 09, 2021 (last updated February 22, 2025)
A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an existing installation's directory, a local attacker could hijack accounts of other users running Erlang programs or possibly coerce a service running with "erlsrv.exe" to execute arbitrary code as Local System. This can occur only under specific conditions on Windows with unsafe filesystem permissions.
Attacker Value
Unknown

CVE-2020-35733

Disclosure Date: January 15, 2021 (last updated February 22, 2025)
An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.
Attacker Value
Unknown

CVE-2020-25623

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.
Attacker Value
Unknown

CVE-2020-25750

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2013-3942

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability
Attacker Value
Unknown

CVE-2013-7185

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
PotPlayer 1.5.40688: .avi File Memory Corruption