Show filters
78 Total Results
Displaying 51-60 of 78
Sort by:
Attacker Value
Unknown

CVE-2020-12330

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Improper permissions in the installer for the Intel(R) Falcon 8+ UAS AscTec Thermal Viewer, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2020-16910

Disclosure Date: October 16, 2020 (last updated February 22, 2025)
<p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.</p> <p>The security update addresses the vulnerability by correcting security feature behavior to enforce permissions.</p>
0
Attacker Value
Unknown

CVE-2020-8182

Disclosure Date: October 05, 2020 (last updated February 22, 2025)
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
Attacker Value
Unknown

CVE-2020-6564

Disclosure Date: September 21, 2020 (last updated February 22, 2025)
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-0405

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111
Attacker Value
Unknown

CVE-2020-13308

Disclosure Date: September 15, 2020 (last updated February 22, 2025)
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.
Attacker Value
Unknown

CVE-2019-0233

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Attacker Value
Unknown

CVE-2020-13282

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
Attacker Value
Unknown

CVE-2020-8913

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.
Attacker Value
Unknown

CVE-2020-15113

Disclosure Date: August 05, 2020 (last updated February 21, 2025)
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).