Show filters
284 Total Results
Displaying 91-100 of 284
Sort by:
Attacker Value
Unknown
CVE-2021-31566
Disclosure Date: August 23, 2022 (last updated February 24, 2025)
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.
0
Attacker Value
Unknown
CVE-2021-23177
Disclosure Date: August 23, 2022 (last updated February 24, 2025)
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
0
Attacker Value
Unknown
CVE-2020-28422
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
All versions of package git-archive are vulnerable to Command Injection via the exports function.
0
Attacker Value
Unknown
CVE-2021-34538
Disclosure Date: July 16, 2022 (last updated February 24, 2025)
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.
0
Attacker Value
Unknown
CVE-2021-29281
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.
0
Attacker Value
Unknown
CVE-2022-27438
Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
0
Attacker Value
Unknown
CVE-2022-26280
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
0
Attacker Value
Unknown
CVE-2021-3622
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2020-16156
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
CPAN 2.28 allows Signature Verification Bypass.
0
Attacker Value
Unknown
CVE-2021-39048
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.
0