Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2020-8133
Disclosure Date: November 09, 2020 (last updated February 22, 2025)
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
0
Attacker Value
Unknown
CVE-2020-10286
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.
0
Attacker Value
Unknown
CVE-2020-10284
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but as in xarm_studio 1.3.0 the option is missing from the menu. Assuming manual control, even by forcefully removing the current operator from an active session.
0
Attacker Value
Unknown
CVE-2020-6013
Disclosure Date: July 06, 2020 (last updated February 21, 2025)
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems.
0
Attacker Value
Unknown
CVE-2020-10277
Disclosure Date: June 24, 2020 (last updated February 21, 2025)
There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.
0
Attacker Value
Unknown
CVE-2019-15611
Disclosure Date: February 04, 2020 (last updated February 21, 2025)
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
0