Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2021-09-23 CVE-2020-4805 Insecure Storage of Sensitive Information vulnerability in IBM Edge Application Manager 4.2
IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2021-09-23 CVE-2020-4809 Insecure Storage of Sensitive Information vulnerability in IBM Edge Application Manager 4.2
IBM Edge 4.2 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2021-09-23 CVE-2021-20377 Information Exposure Through an Error Message vulnerability in IBM Security Guardium 11.3
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
2.7
2021-09-20 CVE-2021-25740 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Kubernetes
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
network
high complexity
kubernetes CWE-610
3.1
2021-09-14 CVE-2021-37176 Unspecified vulnerability in Siemens Simcenter Femap 2020.2/2021.1
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions).
local
low complexity
siemens
3.3
2021-09-13 CVE-2021-39212 Unspecified vulnerability in Imagemagick
ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications.
local
high complexity
imagemagick
3.6
2021-09-09 CVE-2021-25451 Improper Authentication vulnerability in Google Android 10.0/11.0/9.0
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
local
low complexity
google CWE-287
3.3
2021-09-09 CVE-2021-25455 Out-of-bounds Read vulnerability in Google Android
OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.
local
low complexity
google CWE-125
3.3
2021-09-09 CVE-2021-25457 Improper Input Validation vulnerability in Google Android 10.0/11.0
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
local
low complexity
google CWE-20
3.3
2021-09-09 CVE-2021-25463 Unspecified vulnerability in Samsung Penup
Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.
local
low complexity
samsung
3.3