Show filters
621 Total Results
Displaying 31-40 of 621
Sort by:
Attacker Value
Unknown

CVE-2021-44019

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to but not identical to CVE-2021-44020 and 44021.
Attacker Value
Unknown

CVE-2021-43793

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed, beta and stable versions of Discourse
0
Attacker Value
Unknown

CVE-2021-43211

Disclosure Date: November 24, 2021 (last updated February 23, 2025)
Windows 10 Update Assistant Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2021-35052

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
Attacker Value
Unknown

CVE-2021-28710

Disclosure Date: November 21, 2021 (last updated February 23, 2025)
certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-level translation (EPT), and IOMMUs. These page tables are presently set up to always be 4 levels deep. However, an IOMMU may require the use of just 3 page table levels. In such a configuration the lop level table needs to be stripped before inserting the root table's address into the hardware pagetable base register. When sharing page tables, Xen erroneously skipped this stripping. Consequently, the guest is able to write to leaf page table entries.
Attacker Value
Unknown

CVE-2021-37938

Disclosure Date: November 18, 2021 (last updated February 23, 2025)
It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks to Dominic Couture for finding this vulnerability.
Attacker Value
Unknown

CVE-2021-42956

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive information including DB Connection string, entire IT infrastructure details, commands executed by IT admin including credentials, secrets, private keys and more.
Attacker Value
Unknown

CVE-2021-23193

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ; 8.40 versions prior to 8.40.2063 (MR4); 8.30 versions prior to 8.30.1454 (MR4) ; 8.20 versions prior to 8.20.1291 (MR6); version 8.10 and prior versions.
Attacker Value
Unknown

CVE-2021-42285

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
Windows Kernel Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2021-42282

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
Active Directory Domain Services Elevation of Privilege Vulnerability
0