Show filters
33 Total Results
Displaying 1-10 of 33
Sort by:
Attacker Value
Unknown
CVE-2020-35658
Disclosure Date: December 23, 2020 (last updated February 22, 2025)
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
0
Attacker Value
Unknown
CVE-2020-26549
Disclosure Date: November 17, 2020 (last updated February 22, 2025)
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.
0
Attacker Value
Unknown
CVE-2020-1908
Disclosure Date: November 03, 2020 (last updated February 22, 2025)
Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.
0
Attacker Value
Unknown
CVE-2020-26183
Disclosure Date: October 15, 2020 (last updated February 22, 2025)
Dell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may exploit this vulnerability to perform 'nsrmmdbd' operations in an unintended manner.
0
Attacker Value
Unknown
CVE-2020-15224
Disclosure Date: October 14, 2020 (last updated February 22, 2025)
In Open Enclave before version 0.12.0, an information disclosure vulnerability exists when an enclave application using the syscalls provided by the sockets.edl is loaded by a malicious host application. An attacker who successfully exploited the vulnerability could read privileged data from the enclave heap across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information otherwise considered confidential in an enclave, which could be used in further compromises. The issue has been addressed in version 0.12.0 and the current master branch. Users will need to to recompile their applications against the patched libraries to be protected from this vulnerability.
0
Attacker Value
Unknown
CVE-2020-26182
Disclosure Date: October 14, 2020 (last updated February 22, 2025)
Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manner. The vulnerability is not exploitable by users authenticated via LDAP.
0
Attacker Value
Unknown
CVE-2020-15175
Disclosure Date: October 07, 2020 (last updated February 22, 2025)
In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for the files directory. Any user becomes able to read all the files and folders contained in “/files/”. Some of the sensitive information that is compromised are the user sessions, logs, and more. An attacker would be able to get the Administrators session token and use that to authenticate. The issue is patched in version 9.5.2.
0
Attacker Value
Unknown
CVE-2020-25636
Disclosure Date: October 05, 2020 (last updated February 22, 2025)
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processes. This issue affects mainly the service availability.
0
Attacker Value
Unknown
CVE-2020-13953
Disclosure Date: September 30, 2020 (last updated February 22, 2025)
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
0
Attacker Value
Unknown
CVE-2020-11641
Disclosure Date: September 29, 2020 (last updated February 22, 2025)
A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensitive files from SiteManager instances.
0