Show filters
61 Total Results
Displaying 41-50 of 61
Sort by:
Attacker Value
Unknown

CVE-2019-19561

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
Attacker Value
Unknown

CVE-2020-4886

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system. IBM X-Force ID: 190910.
Attacker Value
Unknown

CVE-2020-4650

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.
Attacker Value
Unknown

CVE-2019-8790

Disclosure Date: October 27, 2020 (last updated February 22, 2025)
This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.
Attacker Value
Unknown

CVE-2020-13937

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.
Attacker Value
Unknown

CVE-2020-26104

Disclosure Date: September 25, 2020 (last updated February 22, 2025)
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
Attacker Value
Unknown

CVE-2020-15775

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.
Attacker Value
Unknown

CVE-2020-4315

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 177234.
Attacker Value
Unknown

CVE-2020-4344

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.
Attacker Value
Unknown

CVE-2020-4171

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
IBM Security Guardium Insights 2.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174407.