Show filters
424 Total Results
Displaying 41-50 of 424
Sort by:
Attacker Value
Unknown
CVE-2021-3631
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2022-25010
Disclosure Date: March 01, 2022 (last updated February 23, 2025)
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
0
Attacker Value
Unknown
CVE-2022-24327
Disclosure Date: February 25, 2022 (last updated February 23, 2025)
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
0
Attacker Value
Unknown
CVE-2022-0247
Disclosure Date: February 25, 2022 (last updated February 23, 2025)
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.
0
Attacker Value
Unknown
CVE-2021-42855
Disclosure Date: February 23, 2022 (last updated February 23, 2025)
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by the "/api/appInternals/1.0/agent/configuration" API to map the corresponding ID to a command to be executed.
0
Attacker Value
Unknown
CVE-2021-3557
Disclosure Date: February 16, 2022 (last updated February 23, 2025)
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.
0
Attacker Value
Unknown
CVE-2021-44521
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
0
Attacker Value
Unknown
CVE-2022-0483
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53
0
Attacker Value
Unknown
CVE-2022-0532
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
0
Attacker Value
Unknown
CVE-2021-39992
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
0