Page 2 of 10 results (0.004 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key. 1Password SCIM Bridge versiones anteriores a 1.6.2, maneja inapropiadamente la comprobación de las solicitudes autenticadas de archivos de registro, lo que lleva a la divulgación de una clave privada TLS • https://app-updates.agilebits.com/product_history/SCIM https://support.1password.com/kb/202102 • CWE-287: Improper Authentication •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption. Se detectó un problema en las versiones beta de la herramienta de línea de comandos 1Password versiones anteriores a 0.5.5 y en las versiones beta de 1Password SCIM bridge anteriores a 0.7.3. Se usó un generador de números aleatorios no seguro para generar varias claves. • https://support.1password.com/command-line https://support.1password.com/kb/202010 https://support.1password.com/scim •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

AgileBits 1Password through 1.0.9.340 allows security feature bypass AgileBits 1Password por medio de 1.0.9.340, permite omitir la característica de seguridad. • https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18986 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.9EPSS: 2%CPEs: 1EXPL: 1

The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is possible to crash the 1Password instance. La aplicación 1Password 6.8 para Android se ha visto afectada por una vulnerabilidad de denegación de servicio (DoS). Al comenzar las actividades com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity o com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity desde una aplicación externa (ya que están exportadas), es posible provocar el cierre inesperado de la instancia de 1Password. 1Password versions prior to 7.0 suffer from a denial of service vulnerability. • https://www.exploit-db.com/exploits/46165 https://app-updates.agilebits.com/product_history/OPA4 https://www.valbrux.it/blog/2019/01/22/cve-2018-13042-1password-android-7-0-denial-of-service • CWE-20: Improper Input Validation •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 2

Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handled in a View Troubleshooting Report action. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en el Sistema de Solución de Problemas en AgileBits 1Password v3.9.9 podría permitir a atacantes remotos inyectar secuencias de comandos web o HTML a través de una cabecera HTTP User-Agent modificada que no gestionada adecuadamente en una acción "Ver informe de solución de problemas". • http://packetstormsecurity.org/files/118467/Agilebits-1Password-3.9.9-Cross-Site-Scripting.html http://www.youtube.com/watch?v=A1kPL9ggRi4 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •