Show filters
1,213 Total Results
Displaying 11-20 of 1,213
Sort by:
Attacker Value
Unknown
CVE-2025-24864
Disclosure Date: March 06, 2025 (last updated March 06, 2025)
Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.
0
Attacker Value
Unknown
CVE-2025-22447
Disclosure Date: March 06, 2025 (last updated March 06, 2025)
Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.
0
Attacker Value
Unknown
CVE-2025-27682
Disclosure Date: March 05, 2025 (last updated March 06, 2025)
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005.
0
Attacker Value
Unknown
CVE-2025-27677
Disclosure Date: March 05, 2025 (last updated March 06, 2025)
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links For Unprivileged File Interaction V-2022-002.
0
Attacker Value
Unknown
CVE-2025-27154
Disclosure Date: February 27, 2025 (last updated February 28, 2025)
Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to version 2.25.1, the file created has `rw-r--r--` (644) permissions by default, when it could be locked down to `rw-------` (600) permissions. This leads to overly broad exposure of the spotify auth token. If this token can be read by an attacker (another user on the machine, or a process running as another user), it can be used to perform administrative actions on the Spotify account, depending on the scope granted to the token. Version 2.25.1 tightens the cache file permissions.
0
Attacker Value
Unknown
CVE-2024-56525
Disclosure Date: February 24, 2025 (last updated February 26, 2025)
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.
0
Attacker Value
Unknown
CVE-2024-46975
Disclosure Date: February 22, 2025 (last updated February 23, 2025)
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.
0
Attacker Value
Unknown
CVE-2025-21106
Disclosure Date: February 20, 2025 (last updated February 27, 2025)
Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive resources in the system.
0
Attacker Value
Unknown
CVE-2024-42419
Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-39286
Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 may allow an authenticated user to potentially enable information disclosure via local access.
0