2 results (0.005 seconds)

CVSS: 7.2EPSS: 1%CPEs: 4EXPL: 0

11 Feb 2021 — vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability which may allow an authenticated admin user to perform a remote code execution. vSphere Replication versiones 8.3.x anteriores a 8.3.1.2, versiones 8.2.x anteriores a 8.2.1.1, versiones 8.1.x anteriores a 8.1.2.3 y versiones 6.5.x anteriores a 6.5.1.5, contienen una vulnerabilidad de inyección de comando posterior a la autenticaci... • https://www.vmware.com/security/advisories/VMSA-2021-0001.html • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 7.0EPSS: 0%CPEs: 33EXPL: 2

23 Oct 2020 — In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack... • https://bugs.eclipse.org/bugs/show_bug.cgi?id=567921 • CWE-377: Insecure Temporary File CWE-378: Creation of Temporary File With Insecure Permissions CWE-379: Creation of Temporary File in Directory with Insecure Permissions •