Show filters
664 Total Results
Displaying 151-160 of 664
Sort by:
Attacker Value
Unknown

CVE-2022-4630

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
Attacker Value
Unknown

CVE-2022-42949

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
Attacker Value
Unknown

CVE-2022-23536

Disclosure Date: December 19, 2022 (last updated February 24, 2025)
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Alertmanager Set Configuration API. Only users of the Alertmanager service where `-experimental.alertmanager.enable-api` or `enable_api: true` is configured are affected. Affected Cortex users are advised to upgrade to patched versions 1.13.2 or 1.14.1. However as a workaround, Cortex administrators may reject Alertmanager configurations containing the `api_key_file` setting in the `opsgenie_configs` section before sending to the Set Alertmanager Configuration API.
Attacker Value
Unknown

CVE-2022-43517

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges.
Attacker Value
Unknown

CVE-2022-42972

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
Attacker Value
Unknown

CVE-2022-23143

Disclosure Date: December 05, 2022 (last updated February 24, 2025)
ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files.
Attacker Value
Unknown

CVE-2022-46338

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data.
Attacker Value
Unknown

CVE-2022-45307

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder.
Attacker Value
Unknown

CVE-2022-45306

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.
Attacker Value
Unknown

CVE-2022-45305

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder.