Show filters
250 Total Results
Displaying 81-90 of 250
Sort by:
Attacker Value
Unknown

CVE-2021-27852

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.
Attacker Value
Unknown

CVE-2021-22153

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user.
Attacker Value
Unknown

CVE-2021-22154

Disclosure Date: May 13, 2021 (last updated November 28, 2024)
An Information Disclosure vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially gain access to a victim's web history.
Attacker Value
Unknown

CVE-2021-22152

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
A Denial of Service due to Improper Input Validation vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially to prevent any new user connections.
Attacker Value
Unknown

CVE-2021-22155

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10.1, 9.1 and earlier could allow an attacker to potentially gain access to the application in the context of the targeted user’s account.
Attacker Value
Unknown

CVE-2021-20085

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.
Attacker Value
Unknown

CVE-2020-25902

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from users who join the class. NOTE: Third-parties dispute the validity of this entry as a possible false positive during research
Attacker Value
Unknown

CVE-2020-8289

Disclosure Date: December 27, 2020 (last updated February 22, 2025)
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.
Attacker Value
Unknown

CVE-2020-8290

Disclosure Date: December 27, 2020 (last updated February 22, 2025)
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.
Attacker Value
Unknown

CVE-2020-6933

Disclosure Date: October 14, 2020 (last updated February 22, 2025)
An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and earlier) could allow an attacker to potentially cause a Denial of Service (DoS) of the UEM Core service.