Show filters
264 Total Results
Displaying 31-40 of 264
Sort by:
Attacker Value
Unknown
CVE-2021-36928
Disclosure Date: August 26, 2021 (last updated February 23, 2025)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2021-30968
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to bypass certain Privacy preferences.
0
Attacker Value
Unknown
CVE-2021-30855
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. An application may be able to access restricted files.
0
Attacker Value
Unknown
CVE-2021-32825
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee43806126012066aad4 there is a "zipslip" vulnerability. The unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations outside the designated target folder. This issue may lead to arbitrary file write (with same permissions as the program running the unpack operation) if the attacker can control the archive file. Additionally, if the attacker has read access to the unpacked files, he may be able to read arbitrary system files the parent process has permissions to read. For more details including a PoC see the referenced GHSL-2020-258.
0
Attacker Value
Unknown
CVE-2021-26426
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Windows User Account Profile Picture Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2021-26425
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Windows Event Tracing Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2021-38570
Disclosure Date: August 11, 2021 (last updated February 23, 2025)
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (during uninstallation) via a symlink.
0
Attacker Value
Unknown
CVE-2021-38511
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.
0
Attacker Value
Unknown
CVE-2021-21594
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerability. It can lead to potential disclosure of sensitive data. Dell recommends upgrading at your earliest opportunity.
0
Attacker Value
Unknown
CVE-2021-21740
Disclosure Date: August 09, 2021 (last updated February 23, 2025)
There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The attacker could insert the USB disk with the symbolic link into the residential gateway, and access unauthorized directory information through the symbolic link, causing information leak.
0