HackAndPwn
Security & Vulnerability Researcher / Professional Penetration Tester

Home

  • CVE-2023-23594

    Some versions of SATO printer firmware contain insufficient access controls in the web GUI that could allow unauthorized users to access printer web configurations with a simple authentication bypass.


  • CVE-2022-34102

    A vulnerability in the Crestron AirMedia Windows application 4.3.1.39 allows a user to pause the uninstallation of an executable to gain a SYSTEM-level command prompt.


  • CVE-2022-36415

    A DLL hijacking vulnerability exists in the uninstaller in Scooter Beyond Compare 1.8a through 4.4.2 before 4.4.3 when installed via the EXE installer. The uninstaller attempts to load DLLs out of a Windows Temp folder. If a standard user places malicious DLLs in the C:\Windows\Temp\ folder, and then the uninstaller is run as SYSTEM, the DLLs will execute with elevated privileges.


  • CVE-2022-36414

    There is an elevation of privilege breakout vulnerability in the Windows EXE installer in Scooter Beyond Compare 4.2.0 through 4.4.2 before 4.4.3. Affected versions allow a logged-in user to run applications with elevated privileges via the Clipboard Compare tray app after installation.


  • CVE-2022-30570

    The Column Based Security component of TIBCO Software Inc.’s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with network access to obtain read access to application information on the affected system. Affected releases are TIBCO Software Inc.’s TIBCO Data Virtualization: versions 8.5.2 and below and TIBCO Data Virtualization for AWS Marketplace: versions 8.5.2 and below.



     Page: 8 of 21     
buy me a coffee