Show filters
284 Total Results
Displaying 91-100 of 284
Sort by:
Attacker Value
Unknown

CVE-2021-31566

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.
Attacker Value
Unknown

CVE-2021-23177

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
Attacker Value
Unknown

CVE-2020-28422

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
All versions of package git-archive are vulnerable to Command Injection via the exports function.
Attacker Value
Unknown

CVE-2021-34538

Disclosure Date: July 16, 2022 (last updated February 24, 2025)
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.
Attacker Value
Unknown

CVE-2021-29281

Disclosure Date: July 07, 2022 (last updated February 24, 2025)
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.
Attacker Value
Unknown

CVE-2022-27438

Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
Attacker Value
Unknown

CVE-2022-26280

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
Attacker Value
Unknown

CVE-2021-3622

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-16156

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
CPAN 2.28 allows Signature Verification Bypass.
Attacker Value
Unknown

CVE-2021-39048

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.