Show filters
424 Total Results
Displaying 321-330 of 424
Sort by:
Attacker Value
Unknown

CVE-2022-40959

Disclosure Date: December 22, 2022 (last updated February 24, 2025)
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
Attacker Value
Unknown

CVE-2022-3166

Disclosure Date: December 16, 2022 (last updated February 24, 2025)
Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with network access to the affected systems by sending TCP packets to webserver and closing it abruptly which would cause a denial-of-service condition for the web server application on the device
Attacker Value
Unknown

CVE-2022-34354

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be read by another user on the system. IBM X-Force ID: 230424.
Attacker Value
Unknown

CVE-2022-34312

Disclosure Date: November 14, 2022 (last updated February 24, 2025)
IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 229447.
Attacker Value
Unknown

CVE-2022-33973

Disclosure Date: November 11, 2022 (last updated February 24, 2025)
Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2022-41876

Disclosure Date: November 10, 2022 (last updated February 24, 2025)
ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically administrators and editors. This issue has been patched in versions 2.3.12, and 1.0.13 on the 1.X branch. Users unable to upgrade can remove the "passwordHash" entry from "src/bundle/Resources/config/graphql/User.types.yaml" in the GraphQL package, and other properties like hash type, email, login if you prefer.
Attacker Value
Unknown

CVE-2022-28170

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.
Attacker Value
Unknown

CVE-2022-41320

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.
Attacker Value
Unknown

CVE-2022-37835

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and information about the server, without admin privileges.
Attacker Value
Unknown

CVE-2022-35513

Disclosure Date: September 07, 2022 (last updated February 24, 2025)
The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.