Show filters
672 Total Results
Displaying 51-60 of 672
Sort by:
Attacker Value
Unknown
CVE-2022-22509
Disclosure Date: January 25, 2022 (last updated February 23, 2025)
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
0
Attacker Value
Unknown
CVE-2021-45222
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege escalation by HR personnel.
0
Attacker Value
Unknown
CVE-2022-21699
Disclosure Date: January 19, 2022 (last updated February 23, 2025)
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.
0
Attacker Value
Unknown
CVE-2022-0090
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.
0
Attacker Value
Unknown
CVE-2021-34998
Disclosure Date: January 13, 2022 (last updated February 23, 2025)
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the use of named pipes. The issue results from allowing an untrusted process to impersonate the client of a pipe. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-14208.
0
Attacker Value
Unknown
CVE-2021-43860
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the case that there's a null byte in the metadata file of an app. Therefore apps can grant themselves permissions without the consent of the user. Flatpak shows permissions to the user during install by reading them from the "xa.metadata" key in the commit metadata. This cannot contain a null terminator, because it is an untrusted GVariant. Flatpak compares these permissions to the *actual* metadata, from the "metadata" file to ensure it wasn't lied to. However, the actual metadata contents are loaded in several places where they are read as simple C-style strings. That means that, if the metadata file includes a null terminator, only the content of the file from *before* the terminator gets compared to xa.metadata.…
0
Attacker Value
Unknown
CVE-2021-42562
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users.
0
Attacker Value
Unknown
CVE-2022-21902
Disclosure Date: January 11, 2022 (last updated February 23, 2025)
Windows DWM Core Library Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2022-0144
Disclosure Date: January 11, 2022 (last updated February 23, 2025)
shelljs is vulnerable to Improper Privilege Management
0
Attacker Value
Unknown
CVE-2022-22266
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
0