Show filters
880 Total Results
Displaying 261-270 of 880
Sort by:
Attacker Value
Unknown

CVE-2023-35308

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Windows MSHTML Platform Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2023-35870

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted, hence making the resource temporarily unavailable.
Attacker Value
Unknown

CVE-2023-33990

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an attacker to perform a Denial of Service. Further, an attacker might be able to modify sensitive data in shared memory objects.This issue only affects SAP SQL Anywhere on Windows. Other platforms are not impacted.
Attacker Value
Unknown

CVE-2022-44719

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.
Attacker Value
Unknown

CVE-2023-37237

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
Attacker Value
Unknown

CVE-2023-35800

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.
Attacker Value
Unknown

CVE-2023-35799

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.
Attacker Value
Unknown

CVE-2023-35168

Disclosure Date: June 26, 2023 (last updated February 25, 2025)
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has a privilege bypass vulnerability where ordinary users can gain access to the user database. Exposed information includes md5 hashes of passwords, username, email, and phone number. The vulnerability has been fixed in v1.18.8. Users are advised to upgrade. There are no known workarounds for the vulnerability.
Attacker Value
Unknown

CVE-2023-29860

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.
Attacker Value
Unknown

CVE-2023-3256

Disclosure Date: June 22, 2023 (last updated February 25, 2025)
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.