Total
2747 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-3703 | 1 Opensuse | 1 Open Build Service | 2023-11-07 | 4.0 MEDIUM | 6.5 MEDIUM |
The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data. | |||||
CVE-2011-4183 | 1 Opensuse | 1 Open Build Service | 2023-11-07 | 7.5 HIGH | 9.8 CRITICAL |
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16. | |||||
CVE-2023-21393 | 1 Google | 1 Android | 2023-11-07 | N/A | 7.8 HIGH |
In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-21388 | 1 Google | 1 Android | 2023-11-07 | N/A | 7.8 HIGH |
In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-21389 | 1 Google | 1 Android | 2023-11-07 | N/A | 7.8 HIGH |
In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-21328 | 1 Google | 1 Android | 2023-11-07 | N/A | 7.8 HIGH |
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-21329 | 1 Google | 1 Android | 2023-11-07 | N/A | 5.5 MEDIUM |
In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-21340 | 1 Google | 1 Android | 2023-11-07 | N/A | 5.5 MEDIUM |
In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-21341 | 1 Google | 1 Android | 2023-11-07 | N/A | 7.8 HIGH |
In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-21321 | 1 Google | 1 Android | 2023-11-06 | N/A | 5.5 MEDIUM |
In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-21313 | 1 Google | 1 Android | 2023-11-06 | N/A | 7.8 HIGH |
In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2023-43488 | 1 Boschrexroth | 6 Ctrlx Hmi Web Panel Wr2107, Ctrlx Hmi Web Panel Wr2107 Firmware, Ctrlx Hmi Web Panel Wr2110 and 3 more | 2023-11-06 | N/A | 7.8 HIGH |
The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without requiring the physical access through USB. | |||||
CVE-2023-21373 | 1 Google | 1 Android | 2023-11-04 | N/A | 7.8 HIGH |
In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2022-34794 | 1 Jenkins | 1 Recipe | 2023-11-03 | 4.0 MEDIUM | 6.5 MEDIUM |
Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML. | |||||
CVE-2022-34206 | 1 Jenkins | 1 Jianliao Notification | 2023-11-03 | 4.0 MEDIUM | 4.3 MEDIUM |
A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL. | |||||
CVE-2022-34208 | 1 Jenkins | 1 Beaker Builder | 2023-11-03 | 4.0 MEDIUM | 4.3 MEDIUM |
A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. | |||||
CVE-2022-34210 | 1 Jenkins | 1 Threadfix | 2023-11-03 | 4.0 MEDIUM | 6.5 MEDIUM |
A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. | |||||
CVE-2022-34212 | 1 Jenkins | 1 Vrealize Orchestrator | 2023-11-03 | 3.5 LOW | 5.7 MEDIUM |
A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL. | |||||
CVE-2022-34779 | 1 Jenkins | 1 Xebialabs Xl Release | 2023-11-03 | 4.0 MEDIUM | 4.3 MEDIUM |
A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
CVE-2023-21382 | 1 Google | 1 Android | 2023-11-03 | N/A | 5.5 MEDIUM |
In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. |