Show filters
1,625 Total Results
Displaying 431-440 of 1,625
Sort by:
Attacker Value
Unknown

CVE-2022-3292

Disclosure Date: September 28, 2022 (last updated October 08, 2023)
Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.
Attacker Value
Unknown

CVE-2022-20864

Disclosure Date: September 28, 2022 (last updated October 08, 2023)
A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. This vulnerability is due to a problem with the file and boot variable permissions in ROMMON. An attacker could exploit this vulnerability by rebooting the switch into ROMMON and entering specific commands through the console. A successful exploit could allow the attacker to read any file or reset the enable password.
Attacker Value
Unknown

CVE-2022-20944

Disclosure Date: September 28, 2022 (last updated October 08, 2023)
A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. This vulnerability is due to an improper check in the code function that manages the verification of the digital signatures of system image files during the initial boot process. An attacker could exploit this vulnerability by loading unsigned software on an affected device. A successful exploit could allow the attacker to boot a malicious software image or execute unsigned code and bypass the image verification check part of the boot process of the affected device. To exploit this vulnerability, the attacker needs either unauthenticated physical access to the device or privileged access to the root shell on the device. Note: In Cisco IOS XE Software releases 16.11.1 and later, root shell access is protected by the Consent Token mechanism. However, an attacker wi…
Attacker Value
Unknown

CVE-2022-20662

Disclosure Date: September 28, 2022 (last updated October 08, 2023)
A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability exists because the assigned user of a smart card is not properly matched with the authenticating user. An attacker could exploit this vulnerability by configuring a smart card login to bypass Duo authentication. A successful exploit could allow the attacker to use any personal identity verification (PIV) smart card for authentication, even if the smart card is not assigned to the authenticating user.
Attacker Value
Unknown

CVE-2022-3349

Disclosure Date: September 28, 2022 (last updated October 08, 2023)
A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.
Attacker Value
Unknown

CVE-2022-3048

Disclosure Date: September 26, 2022 (last updated November 08, 2023)
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
Attacker Value
Unknown

CVE-2022-30124

Disclosure Date: September 23, 2022 (last updated October 08, 2023)
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code).
Attacker Value
Unknown

CVE-2022-32872

Disclosure Date: September 20, 2022 (last updated October 08, 2023)
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A person with physical access to an iOS device may be able to access photos from the lock screen.
Attacker Value
Unknown

CVE-2020-36602

Disclosure Date: September 20, 2022 (last updated October 08, 2023)
There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause out-of-bounds read and write.
Attacker Value
Unknown

CVE-2021-33076

Disclosure Date: September 20, 2022 (last updated October 08, 2023)
Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.