Show filters
218 Total Results
Displaying 81-90 of 218
Sort by:
Attacker Value
Unknown
CVE-2020-8092
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens for requests submitted to the Bitdefender Cloud. This issue affects: Bitdefender Bitdefender Antivirus for Mac versions prior to 8.0.0.
0
Attacker Value
Unknown
CVE-2020-3115
Disclosure Date: January 23, 2020 (last updated February 21, 2025)
A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-level privileges on the underlying operating system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted file to the affected system. An exploit could allow the attacker to elevate privileges to root-level privileges.
0
Attacker Value
Unknown
CVE-2019-16017
Disclosure Date: January 08, 2020 (last updated February 22, 2025)
A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to execute Insecure Direct Object Reference actions on specific pages within the OAMP application. The vulnerability is due to insufficient input validation on specific pages of the OAMP application. An attacker could exploit this vulnerability by authenticating to Cisco Unified CVP and sending crafted HTTP requests. A successful exploit could allow an attacker with administrator or read-only privileges to learn information outside of their expected scope. An attacker with administrator privileges could modify certain configuration details of resources outside of their defined scope, which could result in a denial of service (DoS) condition.
0
Attacker Value
Unknown
CVE-2019-14879
Disclosure Date: January 07, 2020 (last updated February 21, 2025)
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
0
Attacker Value
Unknown
CVE-2006-1380
Disclosure Date: March 24, 2006 (last updated February 22, 2025)
ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.
0
Attacker Value
Unknown
CVE-2006-1119
Disclosure Date: March 09, 2006 (last updated February 22, 2025)
fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.
0
Attacker Value
Unknown
CVE-2006-1079
Disclosure Date: March 09, 2006 (last updated February 22, 2025)
htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.
0
Attacker Value
Unknown
CVE-2006-0859
Disclosure Date: February 23, 2006 (last updated February 22, 2025)
Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modified form, possibly related to the nummer parameter.
0
Attacker Value
Unknown
CVE-2006-0700
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.
0
Attacker Value
Unknown
CVE-2006-0697
Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.
0