Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2020-24683
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network communication or endpoints for these applications are not protected, unauthorized actors can bypass authentication and make unauthorized connections to the server application.
0
Attacker Value
Unknown
CVE-2020-5800
Disclosure Date: December 07, 2020 (last updated February 22, 2025)
The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.
0
Attacker Value
Unknown
CVE-2020-15257
Disclosure Date: December 01, 2020 (last updated February 22, 2025)
containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwise restrict access to the abstract Unix domain socket. This would allow malicious containers running in the same network namespace as the shim, with an effective UID of 0 but otherwise reduced privileges, to cause new processes to be run with elevated privileges. This vulnerability has been fixed in containerd 1.3.9 and 1.4.3. Users should update to these versions as soon as they are released. It should be noted that containers started with an old version of containerd-shim should be stopped and restarted, as running containers will continue to be vulnerable even after an upgrade. If you are not providing the ability for untrusted users to …
0
Attacker Value
Unknown
CVE-2020-10778
Disclosure Date: August 11, 2020 (last updated February 21, 2025)
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.
0
Attacker Value
Unknown
CVE-2020-15892
Disclosure Date: July 22, 2020 (last updated February 21, 2025)
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login action from the web interface, the request values are being forwarded to the ssi binary. On the login page, the web interface restricts the password input field to a fixed length of 15 characters. The problem is that validation is being done on the client side, hence it can be bypassed. When an attacker manages to intercept the login request (POST based) and tampers with the vulnerable parameter (log_pass), to a larger length, the request will be forwarded to the webserver. This results in a stack-based buffer overflow. A few other POST variables, (transferred as part of the login request) are also vulnerable: html_response_page and log_user.
0
Attacker Value
Unknown
CVE-2020-5188
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
0
Attacker Value
Unknown
CVE-2020-6862
Disclosure Date: January 17, 2020 (last updated February 21, 2025)
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.
0
Attacker Value
Unknown
CVE-2004-0872
Disclosure Date: September 16, 2004 (last updated February 22, 2025)
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."
0
Attacker Value
Unknown
CVE-2002-0055
Disclosure Date: March 08, 2002 (last updated February 22, 2025)
SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
0