Show filters
188 Total Results
Displaying 81-90 of 188
Sort by:
Attacker Value
Unknown
CVE-2021-44033
Disclosure Date: November 19, 2021 (last updated February 23, 2025)
In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.
0
Attacker Value
Unknown
CVE-2021-42135
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.
0
Attacker Value
Unknown
CVE-2021-41802
Disclosure Date: October 08, 2021 (last updated February 23, 2025)
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.
0
Attacker Value
Unknown
CVE-2021-3145
Disclosure Date: September 10, 2021 (last updated February 23, 2025)
In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
0
Attacker Value
Unknown
CVE-2021-27668
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.
0
Attacker Value
Unknown
CVE-2021-38554
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.
0
Attacker Value
Unknown
CVE-2021-38553
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
0
Attacker Value
Unknown
CVE-2021-2326
Disclosure Date: July 21, 2021 (last updated November 28, 2024)
Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Database Vault. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Database Vault accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
0
Attacker Value
Unknown
CVE-2020-22650
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events.
0
Attacker Value
Unknown
CVE-2021-32923
Disclosure Date: June 03, 2021 (last updated February 22, 2025)
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
0