Show filters
811 Total Results
Displaying 231-240 of 811
Sort by:
Attacker Value
Unknown

CVE-2023-32979

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system.
Attacker Value
Unknown

CVE-2023-32303

Disclosure Date: May 12, 2023 (last updated February 24, 2025)
Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.
Attacker Value
Unknown

CVE-2023-28522

Disclosure Date: May 12, 2023 (last updated February 24, 2025)
IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.
Attacker Value
Unknown

CVE-2023-31445

Disclosure Date: May 11, 2023 (last updated February 24, 2025)
Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.
Attacker Value
Unknown

CVE-2023-0008

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
Attacker Value
Unknown

CVE-2022-46656

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2022-41771

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2022-41699

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2022-41658

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2022-38103

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access