Show filters
686 Total Results
Displaying 161-170 of 686
Sort by:
Attacker Value
Unknown

CVE-2022-44715

Disclosure Date: January 27, 2023 (last updated February 24, 2025)
Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.
Attacker Value
Unknown

CVE-2022-44263

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.
Attacker Value
Unknown

CVE-2023-23610

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to access (including assets, tickets, users, ...). This issue is patched in 10.0.6.
Attacker Value
Unknown

CVE-2023-22592

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permission settings. IBM X-Force ID: 244073.
Attacker Value
Unknown

CVE-2022-34457

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.
Attacker Value
Unknown

CVE-2022-48257

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
Attacker Value
Unknown

CVE-2022-39186

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions
Attacker Value
Unknown

CVE-2022-47927

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.
Attacker Value
Unknown

CVE-2022-43513

Disclosure Date: January 10, 2023 (last updated February 24, 2025)
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename license files with user chosen input without authentication. This could allow an unauthenticated remote attacker to rename and move files as SYSTEM user.
Attacker Value
Unknown

CVE-2014-125059

Disclosure Date: January 07, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in sternenseemann sternenblog. This issue affects the function blog_index of the file main.c. The manipulation of the argument post_path leads to file inclusion. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 0.1.0 is able to address this issue. The identifier of the patch is cf715d911d8ce17969a7926dea651e930c27e71a. It is recommended to upgrade the affected component. The identifier VDB-217613 was assigned to this vulnerability. NOTE: This case is rather theoretical and probably won't happen. Maybe only on obscure Web servers.