Show filters
40 Total Results
Displaying 11-20 of 40
Sort by:
Attacker Value
Unknown
CVE-2020-4126
Disclosure Date: December 01, 2020 (last updated February 22, 2025)
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.
0
Attacker Value
Unknown
CVE-2020-7567
Disclosure Date: November 19, 2020 (last updated February 22, 2025)
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and broke the encryption keys.
0
Attacker Value
Unknown
CVE-2020-8150
Disclosure Date: November 09, 2020 (last updated February 22, 2025)
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
0
Attacker Value
Unknown
CVE-2020-8173
Disclosure Date: November 02, 2020 (last updated February 22, 2025)
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
0
Attacker Value
Unknown
CVE-2020-27651
Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
0
Attacker Value
Unknown
CVE-2020-27650
Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
0
Attacker Value
Unknown
CVE-2020-9774
Disclosure Date: October 27, 2020 (last updated February 22, 2025)
An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting access to encrypted data. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Encrypted data may be inappropriately accessed.
0
Attacker Value
Unknown
CVE-2020-15767
Disclosure Date: September 18, 2020 (last updated February 22, 2025)
An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to obtain it, if the user mistakenly uses a HTTP instead of HTTPS address to access the server. This cookie value could then be used to perform CSRF.
0
Attacker Value
Unknown
CVE-2020-15771
Disclosure Date: September 18, 2020 (last updated February 22, 2025)
An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation.
0
Attacker Value
Unknown
CVE-2020-2239
Disclosure Date: September 01, 2020 (last updated February 22, 2025)
Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
0