Show filters
201 Total Results
Displaying 11-20 of 201
Sort by:
Attacker Value
Unknown
CVE-2021-0336
Disclosure Date: February 10, 2021 (last updated February 22, 2025)
In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local escalation of privilege that bypasses a permission check, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-158219161
0
Attacker Value
Unknown
CVE-2021-23874
Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
0
Attacker Value
Unknown
CVE-2020-26196
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the BackupAdmin role may potentially exploit this vulnerability resulting in the ability to write data outside of the intended file system location.
0
Attacker Value
Unknown
CVE-2020-10553
Disclosure Date: February 05, 2021 (last updated February 22, 2025)
An issue was discovered in Psyprax before 3.2.2. The file %PROGRAMDATA%\Psyprax32\PPScreen.ini contains a hash for the lockscreen (aka screensaver) of the application. If that entry is removed, the lockscreen is no longer displayed and the app is no longer locked. All local users are able to modify that file.
0
Attacker Value
Unknown
CVE-2021-3165
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI.
0
Attacker Value
Unknown
CVE-2020-17522
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these permissions are potentially extended to IP addresses outside the desired range, resulting in them being granted to clients possibly outside the CDN arcitechture.
0
Attacker Value
Unknown
CVE-2020-28482
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts: { path: '/', sameSite: true } 2. The CSRF token was available in the GET query parameter
0
Attacker Value
Unknown
CVE-2021-22850
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.
0
Attacker Value
Unknown
CVE-2021-1126
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is due to clear-text storage and weak permissions of related configuration files. An attacker could exploit this vulnerability by accessing the CLI of the affected software and viewing the contents of the affected files. A successful exploit could allow the attacker to view the credentials that are used to access the proxy server.
0
Attacker Value
Unknown
CVE-2019-4702
Disclosure Date: January 12, 2021 (last updated February 22, 2025)
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
0