Show filters
88 Total Results
Displaying 71-80 of 88
Sort by:
Attacker Value
Unknown

CVE-2020-8190

Disclosure Date: July 10, 2020 (last updated February 21, 2025)
Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
Attacker Value
Unknown

CVE-2020-14958

Disclosure Date: June 21, 2020 (last updated February 21, 2025)
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
Attacker Value
Unknown

CVE-2019-20843

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.
Attacker Value
Unknown

CVE-2019-20846

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.
Attacker Value
Unknown

CVE-2020-13763

Disclosure Date: June 02, 2020 (last updated February 21, 2025)
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
Attacker Value
Unknown

CVE-2020-13230

Disclosure Date: May 20, 2020 (last updated February 21, 2025)
In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).
Attacker Value
Unknown

CVE-2020-2025

Disclosure Date: May 19, 2020 (last updated February 21, 2025)
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and Firecracker based guests.
Attacker Value
Unknown

CVE-2020-9781

Disclosure Date: April 01, 2020 (last updated February 21, 2025)
The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.
Attacker Value
Unknown

CVE-2020-10083

Disclosure Date: March 13, 2020 (last updated February 21, 2025)
GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.
Attacker Value
Unknown

CVE-2020-8634

Disclosure Date: March 07, 2020 (last updated February 21, 2025)
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.