Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

698 CVEs tagged with CWE-36727 Critical, 353 High, 271 Medium, 47 Low, 0 Unrated.

CVE-2022-4149

Published Jun 15, 2023

The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user. Th…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25394

Published May 17, 2023

Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38730

Published Apr 27, 2023

Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2007

Published Apr 24, 2023

The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage…

CVSS 7.8 · High

CVE-2023-0006

Published Apr 12, 2023

A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43946

Published Apr 11, 2023

Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-36…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 451-475 of 698 CVEsPage 19 of 28