Show filters
155 Total Results
Displaying 111-120 of 155
Sort by:
Attacker Value
Unknown

CVE-2020-36219

Disclosure Date: January 26, 2021 (last updated November 28, 2024)
An issue was discovered in the atomic-option crate through 2020-10-31 for Rust. Because AtomicOption<T> implements Sync unconditionally, a data race can occur.
Attacker Value
Unknown

CVE-2020-35897

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the atom crate before 0.3.6 for Rust. An unsafe Send implementation allows a cross-thread data race.
Attacker Value
Unknown

CVE-2020-29578

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
Attacker Value
Unknown

CVE-2020-26649

Disclosure Date: October 22, 2020 (last updated February 22, 2025)
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
Attacker Value
Unknown

CVE-2020-26650

Disclosure Date: October 22, 2020 (last updated February 22, 2025)
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
Attacker Value
Unknown

CVE-2020-5291

Disclosure Date: March 31, 2020 (last updated February 21, 2025)
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unprivileged user namespaces enabled (not default) * Centos 7 flatpak COPR, if unprivileged user namespaces enabled (not default) This has been fixed in the 0.4.1 release, and all affected users should update.
Attacker Value
Unknown

CVE-2013-0193

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0194 and CVE-2013-0195.
Attacker Value
Unknown

CVE-2013-0194

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0195.
Attacker Value
Unknown

CVE-2013-0195

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0194.
Attacker Value
Unknown

CVE-2019-12439

Disclosure Date: May 29, 2019 (last updated November 27, 2024)
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
0