Show filters
978 Total Results
Displaying 491-500 of 978
Sort by:
Attacker Value
Unknown
CVE-2022-36122
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
The Automox Agent before 40 on Windows incorrectly sets permissions on key files.
0
Attacker Value
Unknown
CVE-2022-22248
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
An Incorrect Permission Assignment vulnerability in shell processing of Juniper Networks Junos OS Evolved allows a low-privileged local user to modify the contents of a configuration file which could cause another user to execute arbitrary commands within the context of the follow-on user's session. If the follow-on user is a high-privileged administrator, the attacker could leverage this vulnerability to take complete control of the target system. While this issue is triggered by a user, other than the attacker, accessing the Junos shell, an attacker simply requires Junos CLI access to exploit this vulnerability. This issue affects Juniper Networks Junos OS Evolved: 20.4-EVO versions prior to 20.4R3-S1-EVO; All versions of 21.1-EVO; 21.2-EVO versions prior to 21.2R3-EVO; 21.3-EVO versions prior to 21.3R2-EVO. This issue does not affect Juniper Networks Junos OS Evolved versions prior to 19.2R1-EVO.
0
Attacker Value
Unknown
CVE-2022-26238
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.
0
Attacker Value
Unknown
CVE-2022-26236
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.
0
Attacker Value
Unknown
CVE-2022-39284
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exposed to scripts. It should be noted that this vulnerability does not affect session cookies. Users are advised to upgrade to v4.2.7 or later. Users unable to upgrade are advised to manually construct their cookies either by setting the options in code or by constructing Cookie objects. Examples of each workaround are available in the linked GHSA.
0
Attacker Value
Unknown
CVE-2022-2975
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and 10.1.0.0 through 10.1.0.1. Versions prior to 8.0.0.0 are end of manufacturing support and were not evaluated.
0
Attacker Value
Unknown
CVE-2022-26240
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.
0
Attacker Value
Unknown
CVE-2022-26239
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows unprivileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.
0
Attacker Value
Unknown
CVE-2022-26237
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.
0
Attacker Value
Unknown
CVE-2022-23726
Disclosure Date: September 30, 2022 (last updated February 24, 2025)
PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.
0