Show filters
397 Total Results
Displaying 61-70 of 397
Sort by:
Attacker Value
Unknown

CVE-2021-20874

Disclosure Date: December 24, 2021 (last updated February 23, 2025)
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors.
Attacker Value
Unknown

CVE-2021-35248

Disclosure Date: December 20, 2021 (last updated February 23, 2025)
It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.
Attacker Value
Unknown

CVE-2021-0904

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06076938; Issue ID: ALPS06076938.
Attacker Value
Unknown

CVE-2021-42309

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Microsoft SharePoint Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2021-43065

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows attacker to gain higher privileges via the access to sensitive system data.
Attacker Value
Unknown

CVE-2021-36133

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.
Attacker Value
Unknown

CVE-2021-44512

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.
Attacker Value
Unknown

CVE-2021-43034

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.
Attacker Value
Unknown

CVE-2022-23132

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level
Attacker Value
Unknown

CVE-2021-40101

Disclosure Date: November 30, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.