Show filters
51 Total Results
Displaying 41-50 of 51
Sort by:
Attacker Value
Unknown

CVE-2020-15131

Disclosure Date: July 30, 2020 (last updated February 21, 2025)
In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification. This is fixed in version 1.2.2.
Attacker Value
Unknown

CVE-2020-15130

Disclosure Date: July 30, 2020 (last updated February 21, 2025)
In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group token type as is required by the NFT1 specification. This is fixed in version 0.27.4.
Attacker Value
Unknown

CVE-2020-13485

Disclosure Date: May 25, 2020 (last updated February 21, 2025)
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
Attacker Value
Unknown

CVE-2020-11071

Disclosure Date: May 12, 2020 (last updated February 21, 2025)
SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This is fixed in version 0.27.2.
Attacker Value
Unknown

CVE-2020-11072

Disclosure Date: May 12, 2020 (last updated February 21, 2025)
In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This has been fixed in slp-validate in version 1.2.1. Additonally, slpjs version 0.27.2 has a related fix under related CVE-2020-11071.
Attacker Value
Unknown

CVE-2020-10024

Disclosure Date: May 01, 2020 (last updated February 21, 2025)
The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions.
Attacker Value
Unknown

CVE-2020-10027

Disclosure Date: May 01, 2020 (last updated February 21, 2025)
An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions.
Attacker Value
Unknown

CVE-2020-1741

Disclosure Date: April 24, 2020 (last updated February 21, 2025)
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's browser and the openshift console, could use this flaw to perform a phishing attack. The main threat from this vulnerability is data confidentiality.
Attacker Value
Unknown

CVE-2019-20634

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email headers, it is possible to build a copy-cat Machine Learning Classification model and extract insights from this model. The insights gathered allow an attacker to craft emails that receive preferable scores, with a goal of delivering malicious emails.
Attacker Value
Unknown

CVE-2020-5849

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
Unraid 6.8.0 allows authentication bypass.