Show filters
204 topics marked with the following tags:
Displaying 81-90 of 204
Sort by:
Attacker Value
Moderate
CVE-2024-38023
Disclosure Date: July 09, 2024 (last updated July 12, 2024)
Microsoft SharePoint Server Remote Code Execution Vulnerability
1
Attacker Value
Low
CVE-2022-21839
Disclosure Date: January 11, 2022 (last updated December 21, 2023)
Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability
1
Attacker Value
High
CVE-2022-43769
Disclosure Date: April 03, 2023 (last updated October 08, 2023)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
2
Attacker Value
High
Liferay CE 6.0.2 Java Deserialization
Last updated March 02, 2020
Liferay CE 6.0.2 remote code execution via unsafe deserialization
0
Attacker Value
Low
CVE-2023-27253
Disclosure Date: March 17, 2023 (last updated October 08, 2023)
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
2
Attacker Value
Moderate
CVE-2022-28756
Disclosure Date: August 14, 2022 (last updated October 08, 2023)
The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.
1
Attacker Value
High
CVE-2020-12138
Disclosure Date: April 27, 2020 (last updated October 06, 2023)
AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the virtual address space of the calling process. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages.
1
Attacker Value
Unknown
CVE-2024-26148
Disclosure Date: February 21, 2024 (last updated February 22, 2024)
Querybook is a user interface for querying big data. Prior to version 3.31.1, there is a vulnerability in Querybook's rich text editor that enables users to input arbitrary URLs without undergoing necessary validation. This particular security flaw allows the use of `javascript:` protocol which can potentially trigger arbitrary client-side execution. The most extreme exploit of this flaw could occur when an admin user unknowingly clicks on a cross-site scripting URL, thereby unintentionally compromising admin role access to the attacker. A patch to rectify this issue has been introduced in Querybook version `3.31.1`. The fix is backward compatible and automatically fixes existing DataDocs. There are no known workarounds for this issue, except for manually checking each URL prior to clicking on them.
1
Attacker Value
High
CVE-2022-22942
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.
1
Attacker Value
Moderate
CVE-2020-16205
Disclosure Date: August 14, 2020 (last updated October 07, 2023)
Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5).
1