Show filters
733 Total Results
Displaying 271-280 of 733
Sort by:
Attacker Value
Unknown

CVE-2022-45304

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files located in that folder.
Attacker Value
Unknown

CVE-2022-45301

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.
Attacker Value
Unknown

CVE-2022-41926

Disclosure Date: November 25, 2022 (last updated February 24, 2025)
Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broadcastPermission allowing malicious apps to monitor communication. It is recommended that the Nextcloud Talk Android is upgraded to 14.1.0. There are no known workarounds for this issue.
Attacker Value
Unknown

CVE-2022-44725

Disclosure Date: November 17, 2022 (last updated February 24, 2025)
OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).
Attacker Value
Unknown

CVE-2022-34314

Disclosure Date: November 14, 2022 (last updated February 24, 2025)
IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings. IBM X-Force ID: 229450.
Attacker Value
Unknown

CVE-2022-45193

Disclosure Date: November 12, 2022 (last updated February 24, 2025)
CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation.
Attacker Value
Unknown

CVE-2022-44746

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.
Attacker Value
Unknown

CVE-2022-44733

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
Attacker Value
Unknown

CVE-2022-44732

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
Attacker Value
Unknown

CVE-2022-2188

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.