Show filters
686 Total Results
Displaying 181-190 of 686
Sort by:
Attacker Value
Unknown

CVE-2022-45306

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.
Attacker Value
Unknown

CVE-2022-45305

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder.
Attacker Value
Unknown

CVE-2022-45304

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files located in that folder.
Attacker Value
Unknown

CVE-2022-45301

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.
Attacker Value
Unknown

CVE-2022-41926

Disclosure Date: November 25, 2022 (last updated February 24, 2025)
Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broadcastPermission allowing malicious apps to monitor communication. It is recommended that the Nextcloud Talk Android is upgraded to 14.1.0. There are no known workarounds for this issue.
Attacker Value
Unknown

CVE-2022-44725

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).
Attacker Value
Unknown

CVE-2022-42891

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.
Attacker Value
Unknown

CVE-2022-42733

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.
Attacker Value
Unknown

CVE-2022-42734

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.
Attacker Value
Unknown

CVE-2022-42732

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.