Show filters
813 Total Results
Displaying 391-400 of 813
Sort by:
Attacker Value
Unknown

CVE-2020-25643

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Attacker Value
Unknown

CVE-2020-25735

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.
Attacker Value
Unknown

CVE-2020-25734

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
webTareas through 2.1 allows files/Default/ Directory Listing.
Attacker Value
Unknown

CVE-2020-25733

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
Attacker Value
Unknown

CVE-2020-0427

Disclosure Date: September 17, 2020 (last updated February 22, 2025)
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
Attacker Value
Unknown

CVE-2020-14314

Disclosure Date: September 15, 2020 (last updated February 22, 2025)
A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-23660

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
Attacker Value
Unknown

CVE-2020-24394

Disclosure Date: August 19, 2020 (last updated February 22, 2025)
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.
Attacker Value
Unknown

CVE-2020-3500

Disclosure Date: August 17, 2020 (last updated February 21, 2025)
A vulnerability in the IPv6 implementation of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet to an affected device with the goal of reaching the vulnerable section of the input buffer. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.
Attacker Value
Unknown

CVE-2020-7205

Disclosure Date: July 30, 2020 (last updated November 28, 2024)
A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the specific impacted HPE product and HPE is addressing this issue. HPE has made the following software updates and mitigation information to resolve the vulnerability in Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. HPE provided latest Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting Toolkit which includes the GRUB2 patch to resolve this vulnerability. These new boot images will update GRUB2 and the Forbidden Signature Database (DBX). After the DBX is updated, users will not be able to boot to the older IP, SPP or Scripting ToolKit with Secure Boot enabled. HPE have provided a standalone DBX update tool to work with Micr…