Show filters
1,815 Total Results
Displaying 91-100 of 1,815
Sort by:
Attacker Value
Unknown

CVE-2021-27364

Disclosure Date: March 07, 2021 (last updated February 22, 2025)
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
Attacker Value
Unknown

CVE-2020-16128

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
Attacker Value
Unknown

CVE-2020-27349

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
Attacker Value
Unknown

CVE-2020-27348

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.
Attacker Value
Unknown

CVE-2020-29372

Disclosure Date: November 28, 2020 (last updated February 22, 2025)
An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e.
Attacker Value
Unknown

CVE-2020-0569

Disclosure Date: November 23, 2020 (last updated February 22, 2025)
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
Attacker Value
Unknown

CVE-2020-16123

Disclosure Date: November 23, 2020 (last updated February 22, 2025)
An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to expose sensitive information. Fixed in 1:13.99.3-1ubuntu2, 1:13.99.2-1ubuntu2.1, 1:13.99.1-1ubuntu3.8, 1:11.1-1ubuntu7.11, and 1:8.0-0ubuntu3.15.
Attacker Value
Unknown

CVE-2020-28039

Disclosure Date: November 02, 2020 (last updated November 08, 2023)
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
Attacker Value
Unknown

CVE-2020-28040

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
Attacker Value
Unknown

CVE-2020-14837

Disclosure Date: October 21, 2020 (last updated November 28, 2024)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
0