Show filters
481 Total Results
Displaying 121-130 of 481
Sort by:
Attacker Value
Unknown

CVE-2022-21946

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any running cscreen seesion. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.
Attacker Value
Unknown

CVE-2021-3631

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
Attacker Value
Unknown

CVE-2022-25010

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
Attacker Value
Unknown

CVE-2022-24327

Disclosure Date: February 25, 2022 (last updated February 23, 2025)
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
Attacker Value
Unknown

CVE-2022-0247

Disclosure Date: February 25, 2022 (last updated February 23, 2025)
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.
Attacker Value
Unknown

CVE-2022-25151

Disclosure Date: February 23, 2022 (last updated February 23, 2025)
Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination with a successful Cross-Site Scripting attack on a user.
Attacker Value
Unknown

CVE-2021-42855

Disclosure Date: February 23, 2022 (last updated February 23, 2025)
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by the "/api/appInternals/1.0/agent/configuration" API to map the corresponding ID to a command to be executed.
Attacker Value
Unknown

CVE-2021-3557

Disclosure Date: February 16, 2022 (last updated February 23, 2025)
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.
Attacker Value
Unknown

CVE-2021-44521

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
Attacker Value
Unknown

CVE-2022-0483

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53