Show filters
34 Total Results
Displaying 1-10 of 34
Sort by:
Attacker Value
Low
CVE-2020-0543 CROSSTALK
Disclosure Date: June 15, 2020 (last updated February 21, 2025)
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
1
Attacker Value
Unknown
CVE-2020-36322
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950.
0
Attacker Value
Unknown
CVE-2021-26833
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms. A threat actor can obtain sensitive user data by decoding the tokens as JWT is signed and encoded, not encrypted.
0
Attacker Value
Unknown
CVE-2020-24458
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
Incomplete cleanup in some Intel(R) PROSet/Wireless WiFi and Killer (TM) drivers before version 22.0 may allow a privileged user to potentially enable information disclosure and denial of service<b> </b>via adjacent access.
0
Attacker Value
Unknown
CVE-2019-25016
Disclosure Date: January 28, 2021 (last updated February 22, 2025)
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue.
0
Attacker Value
Unknown
CVE-2020-13451
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.
0
Attacker Value
Unknown
CVE-2020-27888
Disclosure Date: October 27, 2020 (last updated February 22, 2025)
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provide unintended network access.
0
Attacker Value
Unknown
CVE-2019-8732
Disclosure Date: October 27, 2020 (last updated February 22, 2025)
The issue was addressed with improved data deletion. This issue is fixed in iOS 13. Deleted calls remained visible on the device.
0
Attacker Value
Unknown
CVE-2020-13346
Disclosure Date: October 07, 2020 (last updated February 22, 2025)
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
0
Attacker Value
Unknown
CVE-2020-5987
Disclosure Date: October 02, 2020 (last updated February 22, 2025)
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which guest-supplied parameters remain writable by the guest after the plugin has validated them, which may lead to the guest being able to pass invalid parameters to plugin handlers, which may lead to denial of service or escalation of privileges. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.
0