Show filters
397 Total Results
Displaying 61-70 of 397
Sort by:
Attacker Value
Unknown
CVE-2021-20874
Disclosure Date: December 24, 2021 (last updated February 23, 2025)
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-35248
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.
0
Attacker Value
Unknown
CVE-2021-0904
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06076938; Issue ID: ALPS06076938.
0
Attacker Value
Unknown
CVE-2021-42309
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Microsoft SharePoint Server Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2021-43065
Disclosure Date: December 09, 2021 (last updated February 23, 2025)
A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows attacker to gain higher privileges via the access to sensitive system data.
0
Attacker Value
Unknown
CVE-2021-36133
Disclosure Date: December 07, 2021 (last updated February 23, 2025)
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.
0
Attacker Value
Unknown
CVE-2021-44512
Disclosure Date: December 07, 2021 (last updated February 23, 2025)
World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.
0
Attacker Value
Unknown
CVE-2021-43034
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.
0
Attacker Value
Unknown
CVE-2022-23132
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level
0
Attacker Value
Unknown
CVE-2021-40101
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
0