Show filters
54 Total Results
Displaying 41-50 of 54
Sort by:
Attacker Value
Unknown
CVE-2021-26711
Disclosure Date: February 05, 2021 (last updated February 22, 2025)
A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/default.htm turl parameter.
0
Attacker Value
Unknown
CVE-2020-6105
Disclosure Date: October 15, 2020 (last updated February 22, 2025)
An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-0345
Disclosure Date: September 17, 2020 (last updated February 22, 2025)
In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144286721
0
Attacker Value
Unknown
CVE-2020-0267
Disclosure Date: September 17, 2020 (last updated February 22, 2025)
In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app instead of the one the user intended, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139128211
0
Attacker Value
Unknown
CVE-2020-8226
Disclosure Date: August 17, 2020 (last updated February 21, 2025)
A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
0
Attacker Value
Unknown
CVE-2020-5412
Disclosure Date: August 05, 2020 (last updated February 21, 2025)
Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.
0
Attacker Value
Unknown
CVE-2020-8553
Disclosure Date: July 29, 2020 (last updated February 21, 2025)
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.
0
Attacker Value
Unknown
CVE-2020-14057
Disclosure Date: July 01, 2020 (last updated February 21, 2025)
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.
0
Attacker Value
Unknown
CVE-2020-0210
Disclosure Date: June 11, 2020 (last updated February 21, 2025)
In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145206763
0
Attacker Value
Unknown
CVE-2020-5296
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the `cms.manage_assets` permission. Issue has been patched in Build 466 (v1.0.466).
0