Show filters
736 Total Results
Displaying 111-120 of 736
Sort by:
Attacker Value
Unknown
CVE-2020-6431
Disclosure Date: April 13, 2020 (last updated February 21, 2025)
Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2020-6437
Disclosure Date: April 13, 2020 (last updated February 21, 2025)
Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.
0
Attacker Value
Unknown
CVE-2019-14905
Disclosure Date: March 31, 2020 (last updated February 21, 2025)
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
0
Attacker Value
Unknown
CVE-2020-6802
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
0
Attacker Value
Unknown
CVE-2020-1747
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.
0
Attacker Value
Unknown
CVE-2020-9359
Disclosure Date: March 24, 2020 (last updated November 08, 2023)
KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
0
Attacker Value
Unknown
CVE-2020-10684
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.
0
Attacker Value
Unknown
CVE-2020-6420
Disclosure Date: March 23, 2020 (last updated November 08, 2023)
Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2020-6427
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2020-6424
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0