Show filters
148 Total Results
Displaying 31-40 of 148
Sort by:
Attacker Value
Unknown

CVE-2020-14418

Disclosure Date: January 30, 2021 (last updated February 22, 2025)
A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to elevate their privileges to SYSTEM. This occurs because path redirection can occur via vectors involving directory junctions.
Attacker Value
Unknown

CVE-2020-36216

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
An issue was discovered in Input<R> in the eventio crate before 0.5.1 for Rust. Because a non-Send type can be sent to a different thread, a data race and memory corruption can occur.
Attacker Value
Unknown

CVE-2020-7307

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.
Attacker Value
Unknown

CVE-2020-7303

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote user to trigger scripts to run in a user's browser via adding a new label.
Attacker Value
Unknown

CVE-2020-7302

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.
Attacker Value
Unknown

CVE-2020-7305

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials.
Attacker Value
Unknown

CVE-2020-7304

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label.
Attacker Value
Unknown

CVE-2020-7306

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text
Attacker Value
Unknown

CVE-2020-7301

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in the DLP case management section.
Attacker Value
Unknown

CVE-2020-7300

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HTTP post messages.