Show filters
449 Total Results
Displaying 51-60 of 449
Sort by:
Attacker Value
Unknown
CVE-2022-23922
Disclosure Date: February 22, 2022 (last updated February 23, 2025)
WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the Program Announcer directory and elevate permissions whenever the program is executed.
0
Attacker Value
Unknown
CVE-2021-45083
Disclosure Date: February 20, 2022 (last updated February 23, 2025)
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.
0
Attacker Value
Unknown
CVE-2021-3948
Disclosure Date: February 18, 2022 (last updated February 23, 2025)
An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integrity, and availability of the services located on that cluster.
0
Attacker Value
Unknown
CVE-2021-3155
Disclosure Date: February 17, 2022 (last updated February 23, 2025)
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
0
Attacker Value
Unknown
CVE-2022-25327
Disclosure Date: February 16, 2022 (last updated February 23, 2025)
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
0
Attacker Value
Unknown
CVE-2022-23996
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.
0
Attacker Value
Unknown
CVE-2022-23995
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.
0
Attacker Value
Unknown
CVE-2021-39658
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system properties。Product: AndroidVersions: Android SoCAndroid ID: A-207479207
0
Attacker Value
Unknown
CVE-2021-39635
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid ID: A-206492634
0
Attacker Value
Unknown
CVE-2021-20001
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.
0