Show filters
488 Total Results
Displaying 71-80 of 488
Sort by:
Attacker Value
Unknown

CVE-2022-25364

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute malicious code as part of a build. As of 2021.4.2, the built-in build cache is inaccessible-by-default, requiring explicit configuration of its access-control settings before it can be used. (Remote build cache nodes are unaffected as they are inaccessible-by-default.)
Attacker Value
Unknown

CVE-2021-39694

Disclosure Date: March 16, 2022 (last updated February 23, 2025)
In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-202312327
Attacker Value
Unknown

CVE-2022-25815

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
Attacker Value
Unknown

CVE-2022-25814

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
Attacker Value
Unknown

CVE-2021-44216

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
Attacker Value
Unknown

CVE-2021-44215

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
Attacker Value
Unknown

CVE-2021-40059

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect confidentiality.
Attacker Value
Unknown

CVE-2021-40049

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.
Attacker Value
Unknown

CVE-2021-3981

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous versions. This issue has been fixed in grub upstream but no version with the fix is currently released.
Attacker Value
Unknown

CVE-2021-40053

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.