Show filters
339 Total Results
Displaying 31-40 of 339
Sort by:
Attacker Value
Unknown

CVE-2021-22295

Disclosure Date: August 06, 2021 (last updated February 23, 2025)
A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.
Attacker Value
Unknown

CVE-2021-32464

Disclosure Date: August 04, 2021 (last updated February 23, 2025)
An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-33334

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Access in Site Administration" permission to view all forms and form entries in a site via the forms section in site administration.
Attacker Value
Unknown

CVE-2021-33333

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions via crafted URLs.
Attacker Value
Unknown

CVE-2021-33327

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.
Attacker Value
Unknown

CVE-2021-33324

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.
Attacker Value
Unknown

CVE-2020-25593

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.
Attacker Value
Unknown

CVE-2021-0441

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174495520
Attacker Value
Unknown

CVE-2021-0486

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-171430330
Attacker Value
Unknown

CVE-2021-31217

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.