| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient. |
| In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible. |
| In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing. |
| In JetBrains TeamCity before 2021.1.2, user enumeration was possible. |
| In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible. |
| In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. |
| JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. |
| In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. |
| In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. |
| In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. |
| In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. |
| In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. |
| In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. |
| In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. |
| As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N) |
| With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts. |
| An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products. |
| A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific malicious users to inject `NS` records of any domain (even TLDs) into the cache and conduct a DNS cache poisoning attack. |
| An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation bug in the handling of the SRR1 register values. |
| The eFTL Server component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains an easily exploitable vulnerability that allows clients to inherit the permissions of the client that initially connected on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO eFTL - Community Edition: versions 6.7.2 and below, TIBCO eFTL - Developer Edition: versions 6.7.2 and below, and TIBCO eFTL - Enterprise Edition: versions 6.7.2 and below. |