Show filters
980 Total Results
Displaying 621-630 of 980
Sort by:
Attacker Value
Unknown

CVE-2021-35248

Disclosure Date: December 20, 2021 (last updated February 23, 2025)
It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.
Attacker Value
Unknown

CVE-2021-0904

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06076938; Issue ID: ALPS06076938.
Attacker Value
Unknown

CVE-2021-42309

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Microsoft SharePoint Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2021-43065

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows attacker to gain higher privileges via the access to sensitive system data.
Attacker Value
Unknown

CVE-2021-36133

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.
Attacker Value
Unknown

CVE-2021-44512

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.
Attacker Value
Unknown

CVE-2021-43034

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.
Attacker Value
Unknown

CVE-2022-23132

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level
Attacker Value
Unknown

CVE-2021-40101

Disclosure Date: November 30, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
Attacker Value
Unknown

CVE-2021-44230

Disclosure Date: November 30, 2021 (last updated February 23, 2025)
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the compromised account may have inherited read access to sensitive configuration, database, and log files.