Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2021-03-04 CVE-2021-25331 Information Exposure vulnerability in Samsung PAY Mini
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.
low complexity
samsung CWE-200
2.4
2021-03-03 CVE-2021-21331 Unspecified vulnerability in Datadoghq Datadog-Api-Client-Java 1.0.0
The Java client for the Datadog API before version 1.0.0-beta.9 has a local information disclosure of sensitive information downloaded via the API using the API Client.
local
low complexity
datadoghq
3.3
2021-03-02 CVE-2021-22294 Unspecified vulnerability in Huawei Harmonyos 2.0
A component API of the HarmonyOS 2.0 has a permission bypass vulnerability.
local
low complexity
huawei
3.3
2021-03-02 CVE-2020-4726 Insecure Storage of Sensitive Information vulnerability in IBM Cloud Application Performance Management 8.1.4
The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm CWE-922
3.3
2021-03-02 CVE-2020-4725 Unspecified vulnerability in IBM Cloud Application Performance Management 8.1.4
IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially crafted HTTP request to the APM UI, which could mislead another user.
network
low complexity
ibm
3.5
2021-02-26 CVE-2019-18947 Information Exposure Through an Error Message vulnerability in Microfocus Solutions Business Manager
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.
low complexity
microfocus CWE-209
3.5
2021-02-25 CVE-2021-20203 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0.
local
low complexity
qemu fedoraproject debian CWE-190
3.2
2021-02-24 CVE-2021-27645 Double Free vulnerability in multiple products
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system.
local
high complexity
gnu fedoraproject debian CWE-415
2.5
2021-02-23 CVE-2020-27768 In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h.
local
low complexity
imagemagick debian
3.3
2021-02-16 CVE-2021-23839 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
OpenSSL 1.0.2 supports SSLv2.
network
high complexity
openssl oracle siemens CWE-327
3.7