Show filters
421 Total Results
Displaying 111-120 of 421
Sort by:
Attacker Value
Unknown

CVE-2020-6526

Disclosure Date: July 22, 2020 (last updated November 08, 2023)
Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6514

Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
Attacker Value
Unknown

CVE-2020-6524

Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6518

Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-15803

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
Attacker Value
Unknown

CVE-2020-15396

Disclosure Date: June 30, 2020 (last updated February 21, 2025)
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
Attacker Value
Unknown

CVE-2020-14983

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
Attacker Value
Unknown

CVE-2020-8164

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
Attacker Value
Unknown

CVE-2020-14004

Disclosure Date: June 12, 2020 (last updated February 21, 2025)
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be changed to mode 2750 by the unprivileged icinga2 user.
Attacker Value
Unknown

CVE-2020-13696

Disclosure Date: June 08, 2020 (last updated February 21, 2025)
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the existence of arbitrary files and to trigger an open on arbitrary files with mode O_RDWR. To achieve this, relative path components need to be added to the device path, as demonstrated by a v4l-conf -c /dev/../root/.bash_history command.