Show filters
769 Total Results
Displaying 291-300 of 769
Sort by:
Attacker Value
Unknown

CVE-2022-44263

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.
Attacker Value
Unknown

CVE-2023-23610

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to access (including assets, tickets, users, ...). This issue is patched in 10.0.6.
Attacker Value
Unknown

CVE-2023-22592

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permission settings. IBM X-Force ID: 244073.
Attacker Value
Unknown

CVE-2022-34457

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.
Attacker Value
Unknown

CVE-2022-48257

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
Attacker Value
Unknown

CVE-2022-39186

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions
Attacker Value
Unknown

CVE-2022-47927

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.
Attacker Value
Unknown

CVE-2022-4630

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
Attacker Value
Unknown

CVE-2022-42949

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
Attacker Value
Unknown

CVE-2022-43517

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges.