Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2021-04-09 CVE-2021-25358 Incorrect Default Permissions vulnerability in Google Android 10.0/9.0
A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.
local
low complexity
google CWE-276
3.3
2021-04-09 CVE-2021-29671 Unspecified vulnerability in IBM Spectrum Scale 5.1.0.1
IBM Spectrum Scale 5.1.0.1 could allow a local attacker to bypass the filesystem audit logging mechanism when file audit logging is enabled.
local
low complexity
ibm
3.3
2021-04-07 CVE-2020-36314 Link Following vulnerability in multiple products
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations.
local
low complexity
gnome fedoraproject CWE-59
3.9
2021-04-02 CVE-2021-1803 Unspecified vulnerability in Apple Macos
The issue was addressed with improved permissions logic.
local
low complexity
apple
3.3
2021-04-02 CVE-2021-1771 Unspecified vulnerability in Apple mac OS X and Macos
This issue was addressed with improved checks.
local
low complexity
apple
3.3
2021-04-02 CVE-2021-1756 Unspecified vulnerability in Apple Ipados and Iphone OS
A lock screen issue allowed access to contacts on a locked device.
low complexity
apple
2.4
2021-04-02 CVE-2021-1755 Missing Authorization vulnerability in Apple Macos
A lock screen issue allowed access to contacts on a locked device.
low complexity
apple CWE-862
2.4
2021-04-02 CVE-2020-29623 "Clear History and Website Data" did not clear the history.
local
low complexity
apple fedoraproject webkitgtk
3.3
2021-04-01 CVE-2021-21416 Information Exposure Through an Error Message vulnerability in Django-Registration Project Django-Registration
django-registration is a user registration package for Django.
network
high complexity
django-registration-project CWE-209
2.6
2021-04-01 CVE-2021-22890 Authentication Bypass by Spoofing vulnerability in multiple products
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets.
3.7