Show filters
613 Total Results
Displaying 191-200 of 613
Sort by:
Attacker Value
Unknown

CVE-2022-35167

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
Attacker Value
Unknown

CVE-2022-32777

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerabilty is for the session cookie which can be leaked via JavaScript.
Attacker Value
Unknown

CVE-2022-32778

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerability is for the pass cookie, which contains the hashed password and can be leaked via JavaScript.
Attacker Value
Unknown

CVE-2020-1754

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
Attacker Value
Unknown

CVE-2022-22411

Disclosure Date: August 04, 2022 (last updated February 24, 2025)
IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016.
Attacker Value
Unknown

CVE-2022-36800

Disclosure Date: August 03, 2022 (last updated February 24, 2025)
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.
Attacker Value
Unknown

CVE-2021-22648

Disclosure Date: July 28, 2022 (last updated February 24, 2025)
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
Attacker Value
Unknown

CVE-2022-34112

Disclosure Date: July 22, 2022 (last updated February 24, 2025)
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
Attacker Value
Unknown

CVE-2022-1655

Disclosure Date: July 22, 2022 (last updated February 24, 2025)
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
Attacker Value
Unknown

CVE-2022-34891

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update machanism. The product sets incorrect permissions on sensitive files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-16395.