Show filters
980 Total Results
Displaying 661-670 of 980
Sort by:
Attacker Value
Unknown
CVE-2021-3747
Disclosure Date: September 28, 2021 (last updated February 23, 2025)
The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner.
0
Attacker Value
Unknown
CVE-2021-34409
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious actor with local access to a user's machine could use this flaw to potentially run arbitrary system commands in a higher privileged context during the installation process.
0
Attacker Value
Unknown
CVE-2021-34410
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook for Mac before 5.0.25611.0521 allows for privilege escalation to root.
0
Attacker Value
Unknown
CVE-2021-40067
Disclosure Date: September 16, 2021 (last updated February 23, 2025)
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.
0
Attacker Value
Unknown
CVE-2021-40066
Disclosure Date: September 16, 2021 (last updated February 23, 2025)
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.
0
Attacker Value
Unknown
CVE-2021-39210
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may avoid using the "remember me" feature.
0
Attacker Value
Unknown
CVE-2021-22147
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
0
Attacker Value
Unknown
CVE-2021-26434
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Visual Studio Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2021-22149
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.
0
Attacker Value
Unknown
CVE-2021-22148
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their creator. This could lead to a less privileged user gaining access to unauthorized engines.
0