Show filters
628 Total Results
Displaying 201-210 of 628
Sort by:
Attacker Value
Unknown

CVE-2022-37771

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.
Attacker Value
Unknown

CVE-2022-36670

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.
Attacker Value
Unknown

CVE-2022-38170

Disclosure Date: September 02, 2022 (last updated February 24, 2025)
In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users to expose arbitrary file contents via the webserver.
Attacker Value
Unknown

CVE-2022-37435

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.
Attacker Value
Unknown

CVE-2020-27836

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..
Attacker Value
Unknown

CVE-2022-35167

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
Attacker Value
Unknown

CVE-2022-32777

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerabilty is for the session cookie which can be leaked via JavaScript.
Attacker Value
Unknown

CVE-2022-32778

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerability is for the pass cookie, which contains the hashed password and can be leaked via JavaScript.
Attacker Value
Unknown

CVE-2020-1754

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
Attacker Value
Unknown

CVE-2022-22411

Disclosure Date: August 04, 2022 (last updated February 24, 2025)
IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016.