Show filters
188 Total Results
Displaying 1-10 of 188
Sort by:
Attacker Value
Unknown
CVE-2021-25482
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite some CMFA framework information.
0
Attacker Value
Unknown
CVE-2021-25472
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.
0
Attacker Value
Unknown
CVE-2021-28497
Disclosure Date: September 09, 2021 (last updated February 23, 2025)
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train
0
Attacker Value
Unknown
CVE-2021-36879
Disclosure Date: July 27, 2021 (last updated February 23, 2025)
Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.
0
Attacker Value
Unknown
CVE-2021-21438
Disclosure Date: March 22, 2021 (last updated February 22, 2025)
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.
0
Attacker Value
Unknown
CVE-2021-21437
Disclosure Date: March 22, 2021 (last updated February 22, 2025)
Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions
0
Attacker Value
Unknown
CVE-2021-27851
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a build process, for instance with `guix build`, that makes its build directory world-writable. The user then creates a hardlink to a root-owned file such as /etc/shadow in that build directory. If the user passed the --keep-failed option and the build eventually fails, the daemon changes ownership of the whole build tree, including the hardlink, to the user. At that point, the user has write access to the target file. Versions after and including v0.11.0-3298-g2608e40988, and versions prior to v1.2.0-75109-g94f0312546 are vulnerable.
0
Attacker Value
Unknown
CVE-2021-22661
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
Changing the password on the module webpage does not require the user to type in the current password first. Thus, the password could be changed by a user or external process without knowledge of the current password on the ICX35-HWC-A and ICX35-HWC-E (Versions 1.9.62 and prior).
0
Attacker Value
Unknown
CVE-2019-18945
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability.
0
Attacker Value
Unknown
CVE-2021-21436
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.
0