Show filters
94 Total Results
Displaying 81-90 of 94
Sort by:
Attacker Value
Unknown

CVE-2020-13763

Disclosure Date: June 02, 2020 (last updated February 21, 2025)
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
Attacker Value
Unknown

CVE-2020-13230

Disclosure Date: May 20, 2020 (last updated February 21, 2025)
In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).
Attacker Value
Unknown

CVE-2020-2025

Disclosure Date: May 19, 2020 (last updated February 21, 2025)
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and Firecracker based guests.
Attacker Value
Unknown

CVE-2020-9781

Disclosure Date: April 01, 2020 (last updated February 21, 2025)
The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.
Attacker Value
Unknown

CVE-2020-10083

Disclosure Date: March 13, 2020 (last updated February 21, 2025)
GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.
Attacker Value
Unknown

CVE-2020-8634

Disclosure Date: March 07, 2020 (last updated February 21, 2025)
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.
Attacker Value
Unknown

CVE-2020-8633

Disclosure Date: February 18, 2020 (last updated February 21, 2025)
An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calendar in Outlook, the calendar stayed mounted and accessible.
Attacker Value
Unknown

CVE-2020-7063

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.
Attacker Value
Unknown

CVE-2019-15621

Disclosure Date: February 04, 2020 (last updated February 21, 2025)
Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.
Attacker Value
Unknown

CVE-2020-8117

Disclosure Date: February 04, 2020 (last updated February 21, 2025)
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.