Show filters
421 Total Results
Displaying 161-170 of 421
Sort by:
Attacker Value
Unknown

CVE-2020-12050

Disclosure Date: April 30, 2020 (last updated February 21, 2025)
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
Attacker Value
Unknown

CVE-2020-12137

Disclosure Date: April 24, 2020 (last updated February 21, 2025)
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
Attacker Value
Unknown

CVE-2020-12066

Disclosure Date: April 22, 2020 (last updated February 21, 2025)
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
Attacker Value
Unknown

CVE-2020-6450

Disclosure Date: April 13, 2020 (last updated February 21, 2025)
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6438

Disclosure Date: April 13, 2020 (last updated February 21, 2025)
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
Attacker Value
Unknown

CVE-2020-6441

Disclosure Date: April 13, 2020 (last updated February 21, 2025)
Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6452

Disclosure Date: April 13, 2020 (last updated February 21, 2025)
Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6456

Disclosure Date: April 13, 2020 (last updated February 21, 2025)
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.
Attacker Value
Unknown

CVE-2020-6451

Disclosure Date: April 13, 2020 (last updated February 21, 2025)
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6436

Disclosure Date: April 13, 2020 (last updated February 21, 2025)
Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.