Show filters
736 Total Results
Displaying 61-70 of 736
Sort by:
Attacker Value
Unknown

CVE-2021-27766

Disclosure Date: April 21, 2022 (last updated February 23, 2025)
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
Attacker Value
Unknown

CVE-2021-27767

Disclosure Date: April 21, 2022 (last updated February 23, 2025)
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
Attacker Value
Unknown

CVE-2021-27765

Disclosure Date: April 21, 2022 (last updated February 23, 2025)
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
Attacker Value
Unknown

CVE-2022-0070

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
Attacker Value
Unknown

CVE-2021-3100

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
Attacker Value
Unknown

CVE-2021-3101

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full privileges on the host, bypassing restrictions set on the container.
Attacker Value
Unknown

CVE-2022-0071

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or syscall filters of the target JVM process. This would allow a container to exhaust the resources of the host, modify devices, or make syscalls that would otherwise be blocked.
Attacker Value
Unknown

CVE-2021-36784

Disclosure Date: April 15, 2022 (last updated February 23, 2025)
A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.
Attacker Value
Unknown

CVE-2021-4200

Disclosure Date: April 15, 2022 (last updated February 23, 2025)
A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.
Attacker Value
Unknown

CVE-2020-16238

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with command line access to the underlying Linux system to escalate privileges to the root user.