Show filters
117 Total Results
Displaying 11-20 of 117
Sort by:
Attacker Value
Unknown
CVE-2024-37025
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-50583
Disclosure Date: October 25, 2024 (last updated October 25, 2024)
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.
0
Attacker Value
Unknown
CVE-2024-47045
Disclosure Date: September 26, 2024 (last updated September 26, 2024)
Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepared by an attacker may be executed with higher privileges than the application privilege.
0
Attacker Value
Unknown
CVE-2024-23974
Disclosure Date: August 14, 2024 (last updated August 15, 2024)
Incorrect default permissions in some Intel(R) ISH software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-22378
Disclosure Date: August 14, 2024 (last updated August 15, 2024)
Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-43747
Disclosure Date: August 14, 2024 (last updated August 15, 2024)
Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-38177
Disclosure Date: August 13, 2024 (last updated August 17, 2024)
Windows App Installer Spoofing Vulnerability
0
Attacker Value
Unknown
CVE-2024-21583
Disclosure Date: July 19, 2024 (last updated July 19, 2024)
Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/auth before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/public-api-server before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/server before main-gha.27122; versions of the package @gitpod/gitpod-protocol before 0.1.5-main-gha.27122 are vulnerable to Cookie Tossing due to a missing __Host- prefix on the _gitpod_io_jwt2_ session cookie. This allows an adversary who controls a subdomain to set the value of the cookie on the Gitpod control plane, which can be assigned to an attacker’s own JWT so that specific actions taken by the victim (such as connecting a new Github organization) are ac…
0
Attacker Value
Unknown
CVE-2024-32861
Disclosure Date: July 16, 2024 (last updated January 13, 2025)
Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permissions.
0
Attacker Value
Unknown
CVE-2024-21813
Disclosure Date: May 16, 2024 (last updated May 17, 2024)
Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
0