Show filters
54 Total Results
Displaying 41-50 of 54
Sort by:
Attacker Value
Unknown

CVE-2021-26711

Disclosure Date: February 05, 2021 (last updated February 22, 2025)
A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/default.htm turl parameter.
Attacker Value
Unknown

CVE-2020-6105

Disclosure Date: October 15, 2020 (last updated February 22, 2025)
An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-0345

Disclosure Date: September 17, 2020 (last updated February 22, 2025)
In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144286721
Attacker Value
Unknown

CVE-2020-0267

Disclosure Date: September 17, 2020 (last updated February 22, 2025)
In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app instead of the one the user intended, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139128211
Attacker Value
Unknown

CVE-2020-8226

Disclosure Date: August 17, 2020 (last updated February 21, 2025)
A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
Attacker Value
Unknown

CVE-2020-5412

Disclosure Date: August 05, 2020 (last updated February 21, 2025)
Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.
Attacker Value
Unknown

CVE-2020-8553

Disclosure Date: July 29, 2020 (last updated February 21, 2025)
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.
Attacker Value
Unknown

CVE-2020-14057

Disclosure Date: July 01, 2020 (last updated February 21, 2025)
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.
Attacker Value
Unknown

CVE-2020-0210

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145206763
Attacker Value
Unknown

CVE-2020-5296

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).