Vulnerabilities (CVE)

Filtered by CWE-649
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36279 2024-11-21 N/A 5.3 MEDIUM
Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.
CVE-2010-3300 1 Owasp 1 Enterprise Security Api For Java 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.