Show filters
65 Total Results
Displaying 11-20 of 65
Sort by:
Attacker Value
Unknown
CVE-2021-31422
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the e1000e virtual device. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-12527.
0
Attacker Value
Unknown
CVE-2021-31427
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Open Tools Gate component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-13082.
0
Attacker Value
Unknown
CVE-2021-21539
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A remote authenticated attacker could potentially exploit this vulnerability to gain elevated privileges when a user with higher privileges is simultaneously accessing iDRAC through the web interface.
0
Attacker Value
Unknown
CVE-2020-11220
Disclosure Date: March 17, 2021 (last updated February 22, 2025)
While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
0
Attacker Value
Unknown
CVE-2020-11230
Disclosure Date: March 17, 2021 (last updated February 22, 2025)
Potential arbitrary memory corruption when the qseecom driver updates ion physical addresses in the buffer as it exposes a physical address to user land in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
0
Attacker Value
Unknown
CVE-2021-23977
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories. Note: This issue is only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.
0
Attacker Value
Unknown
CVE-2021-26910
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
0
Attacker Value
Unknown
CVE-2020-14418
Disclosure Date: January 30, 2021 (last updated February 22, 2025)
A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.
0
Attacker Value
Unknown
CVE-2021-21615
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
0
Attacker Value
Unknown
CVE-2020-35889
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the crayon crate through 2020-08-31 for Rust. A TOCTOU issue has a resultant memory safety violation via HandleLike.
0