Show filters
811 Total Results
Displaying 231-240 of 811
Sort by:
Attacker Value
Unknown
CVE-2023-32979
Disclosure Date: May 16, 2023 (last updated February 24, 2025)
Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system.
0
Attacker Value
Unknown
CVE-2023-32303
Disclosure Date: May 12, 2023 (last updated February 24, 2025)
Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.
0
Attacker Value
Unknown
CVE-2023-28522
Disclosure Date: May 12, 2023 (last updated February 24, 2025)
IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.
0
Attacker Value
Unknown
CVE-2023-31445
Disclosure Date: May 11, 2023 (last updated February 24, 2025)
Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.
0
Attacker Value
Unknown
CVE-2023-0008
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
0
Attacker Value
Unknown
CVE-2022-46656
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2022-41771
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown
CVE-2022-41699
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2022-41658
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2022-38103
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access
0