Show filters
642 Total Results
Displaying 71-80 of 642
Sort by:
Attacker Value
Unknown

CVE-2022-1365

Disclosure Date: April 15, 2022 (last updated February 23, 2025)
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.
Attacker Value
Unknown

CVE-2021-36778

Disclosure Date: April 15, 2022 (last updated February 23, 2025)
A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.
Attacker Value
Unknown

CVE-2022-29047

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or equivalent), but not able to commit directly to the configured SCM, to effectively change the Pipeline behavior by changing the definition of a dynamically retrieved library in their pull request, even if the Pipeline is configured to not trust them.
Attacker Value
Unknown

CVE-2021-39802

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-213339151References: Upstream kernel
Attacker Value
Unknown

CVE-2021-39799

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-200288596
Attacker Value
Unknown

CVE-2021-0694

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-183147114
Attacker Value
Unknown

CVE-2022-28542

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.
Attacker Value
Unknown

CVE-2022-27836

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary files access.
Attacker Value
Unknown

CVE-2022-27575

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.
Attacker Value
Unknown

CVE-2022-1193

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances