Show filters
421 Total Results
Displaying 111-120 of 421
Sort by:
Attacker Value
Unknown
CVE-2020-6526
Disclosure Date: July 22, 2020 (last updated November 08, 2023)
Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2020-6514
Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
0
Attacker Value
Unknown
CVE-2020-6524
Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2020-6518
Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2020-15803
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
0
Attacker Value
Unknown
CVE-2020-15396
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
0
Attacker Value
Unknown
CVE-2020-14983
Disclosure Date: June 22, 2020 (last updated February 21, 2025)
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
0
Attacker Value
Unknown
CVE-2020-8164
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
0
Attacker Value
Unknown
CVE-2020-14004
Disclosure Date: June 12, 2020 (last updated February 21, 2025)
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be changed to mode 2750 by the unprivileged icinga2 user.
0
Attacker Value
Unknown
CVE-2020-13696
Disclosure Date: June 08, 2020 (last updated February 21, 2025)
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the existence of arbitrary files and to trigger an open on arbitrary files with mode O_RDWR. To achieve this, relative path components need to be added to the device path, as demonstrated by a v4l-conf -c /dev/../root/.bash_history command.
0