Show filters
249 Total Results
Displaying 81-90 of 249
Sort by:
Attacker Value
Unknown

CVE-2021-44224

Disclosure Date: December 20, 2021 (last updated February 23, 2025)
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
Attacker Value
Unknown

CVE-2021-45105

Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Attacker Value
Unknown

CVE-2021-43189

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
Attacker Value
Unknown

CVE-2021-43185

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
Attacker Value
Unknown

CVE-2021-43186

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
Attacker Value
Unknown

CVE-2021-43191

Disclosure Date: November 09, 2021 (last updated November 28, 2024)
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.
Attacker Value
Unknown

CVE-2021-43188

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
Attacker Value
Unknown

CVE-2021-43190

Disclosure Date: November 09, 2021 (last updated November 28, 2024)
In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.
Attacker Value
Unknown

CVE-2021-43192

Disclosure Date: November 09, 2021 (last updated November 28, 2024)
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.
Attacker Value
Unknown

CVE-2021-43187

Disclosure Date: November 09, 2021 (last updated November 28, 2024)
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.