CVE-2021-32985

CVSS v3 Score
7.2
High
CVSS v2 Score
6.5
Medium

Vulnerability Description

AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.

CVSS:7.3(High)

An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.

CVSS:7.3(High)

Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing

CVSS:7.1(High)

In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed

CVSS:7.1(High)

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

CVSS:7.4(High)

Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.

CVSS:7.4(High)

HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actu...