Show filters
291 Total Results
Displaying 21-30 of 291
Sort by:
Attacker Value
Unknown

CVE-2021-29052

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authenticated users to view DDMStructures via GET API calls.
Attacker Value
Unknown

CVE-2020-21342

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
Attacker Value
Unknown

CVE-2021-31519

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-28649

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-26804

Disclosure Date: May 04, 2021 (last updated February 22, 2025)
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
Attacker Value
Unknown

CVE-2021-25317

Disclosure Date: April 30, 2021 (last updated February 22, 2025)
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions.
Attacker Value
Unknown

CVE-2021-3451

Disclosure Date: April 27, 2021 (last updated February 22, 2025)
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written to non-standard locations.
Attacker Value
Unknown

CVE-2021-28271

Disclosure Date: April 27, 2021 (last updated February 22, 2025)
Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions with the 'F' flag (Full) for 'Everyone'and 'Authenticated Users' group.
Attacker Value
Unknown

CVE-2021-25319

Disclosure Date: April 26, 2021 (last updated February 22, 2025)
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.
Attacker Value
Unknown

CVE-2021-20532

Disclosure Date: April 24, 2021 (last updated February 22, 2025)
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to insecure directory permissions. IBM X-Force ID: 198811.