CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-27349

    Last Modified: 21 Nov 2024

    Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.

    Published: 9 Dec 2020
    3.8
    Low

    CVE-2020-16128

    Last Modified: 21 Nov 2024

    The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.

    Published: 9 Dec 2020
    5.7
    Medium

    CVE-2020-10146

    Last Modified: 21 Nov 2024

    The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands. This vulnerability was fixed for all Teams users in the online service on or around October 2020.

    Published: 9 Dec 2020
    8.8
    High

    CVE-2020-26969

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83.

    Published: 9 Dec 2020
    6.5
    Medium

    CVE-2020-26967

    Last Modified: 21 Nov 2024

    When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other than those that it injected into the page. This would lead to internal errors and unexpected behavior in the Screenshots code. This vulnerability affects Firefox < 83.

    Published: 9 Dec 2020
    6.8
    Medium

    CVE-2020-26964

    Last Modified: 19 Aug 2026

    If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

    Published: 9 Dec 2020
    4.3
    Medium

    CVE-2020-26963

    Last Modified: 21 Nov 2024

    Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by introducing rate-limiting to these API calls. This vulnerability affects Firefox < 83.

    Published: 9 Dec 2020
    6.1
    Medium

    CVE-2020-26962

    Last Modified: 21 Nov 2024

    Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

    Published: 9 Dec 2020
    6.5
    Medium

    CVE-2020-26957

    Last Modified: 19 Aug 2026

    OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

    Published: 9 Dec 2020
    6.5
    Medium

    CVE-2020-26955

    Last Modified: 19 Aug 2026

    When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

    Published: 9 Dec 2020
    4.3
    Medium

    CVE-2020-26954

    Last Modified: 19 Aug 2026

    When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

    Published: 9 Dec 2020
    8.8
    High

    CVE-2020-26952

    Last Modified: 21 Nov 2024

    Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially exploitable crash when handling out-of-memory errors. This vulnerability affects Firefox < 83.

    Published: 9 Dec 2020
    6.1
    Medium

    CVE-2020-25627

    Last Modified: 21 Nov 2024

    The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

    Published: 9 Dec 2020
    7.8
    High

    CVE-2020-27614

    Last Modified: 21 Nov 2024

    AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate client requests and allows local privilege escalation.

    Published: 9 Dec 2020
    7.5
    High

    CVE-2020-13988

    Last Modified: 21 Nov 2024

    An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsing TCP MSS options of IPv4 network packets in uip_process in net/ipv4/uip.c.

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-16587

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in ImfMultiPartInputFile.cpp that can cause a denial of service via a crafted EXR file.

    Published: 9 Dec 2020
    8.2
    High

    CVE-2020-17437

    Last Modified: 21 Nov 2024

    An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.

    Published: 9 Dec 2020
    3.1
    Low

    CVE-2020-26418

    Last Modified: 21 Nov 2024

    Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

    Published: 9 Dec 2020
    5.9
    Medium

    CVE-2020-35510

    Last Modified: 21 Nov 2024

    A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB server by writing a sequence of bytes corresponding to the expected messages of a successful EJB client request, but omitting the ACK messages, or just tamper with jboss-remoting code, deleting the lines that send the ACK message from the EJB client code resulting in a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 9 Dec 2020
    7.5
    High

    CVE-2020-8286

    Last Modified: 21 Nov 2024

    curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-16588

    Last Modified: 21 Nov 2024

    A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of service via a crafted EXR file.

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-16589

    Last Modified: 21 Nov 2024

    A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp that can cause a denial of service via a crafted EXR file.

    Published: 9 Dec 2020
    3.1
    Low

    CVE-2020-26420

    Last Modified: 21 Nov 2024

    Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

    Published: 9 Dec 2020
    4.3
    Medium

    CVE-2020-27831

    Last Modified: 21 Nov 2024

    A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

    Published: 9 Dec 2020
    9.1
    Critical

    CVE-2020-36242

    Last Modified: 21 Nov 2024

    In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

    Published: 9 Dec 2020
    7.5
    High

    CVE-2020-13987

    Last Modified: 21 Nov 2024

    An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.

    Published: 9 Dec 2020
    3.1
    Low

    CVE-2020-26419

    Last Modified: 21 Nov 2024

    Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.

    Published: 9 Dec 2020
    4.2
    Medium

    CVE-2020-26421

    Last Modified: 21 Nov 2024

    Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

    Published: 9 Dec 2020
    9
    Critical

    CVE-2020-27832

    Last Modified: 21 Nov 2024

    A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into performing a malicious action to impersonate the target user. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 9 Dec 2020
    6.5
    Medium

    CVE-2021-3611

    Last Modified: 21 Nov 2024

    A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0.

    Published: 9 Dec 2020
    7.7
    High

    CVE-2020-26249

    Last Modified: 21 Nov 2024

    Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before version 0.1.7a an RCE exploit has been discovered. This exploit allows Discord users with specially crafted Server names and Usernames/Nicknames to inject code into the webserver front-end code. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information. This high severity exploit has been fixed on version 0.1.7a. There are no workarounds, bot owners must upgrade their relevant packages (Dashboard module and Dashboard webserver) in order to patch this issue.

    Published: 8 Dec 2020
    4.8
    Medium

    CVE-2020-26234

    Last Modified: 21 Nov 2024

    Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of Opencast's HTTP requests. Hostname verification is an important part when using HTTPS to ensure that the presented certificate is valid for the host. Disabling it can allow for man-in-the-middle attacks. This problem is fixed in Opencast 7.9 and Opencast 8.8 Please be aware that fixing the problem means that Opencast will not simply accept any self-signed certificates any longer without properly importing them. If you need those, please make sure to import them into the Java key store. Better yet, get a valid certificate.

    Published: 8 Dec 2020
    5.7
    Medium

    CVE-2020-26256

    Last Modified: 21 Nov 2024

    Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before version 4.3.6 there is a possible ReDoS vulnerability (Regular Expression Denial of Service) when using ignoreEmpty option when parsing. This has been patched in `v4.3.6` You will only be affected by this if you use the `ignoreEmpty` parsing option. If you do use this option it is recommended that you upgrade to the latest version `v4.3.6` This vulnerability was found using a CodeQL query which identified `EMPTY_ROW_REGEXP` regular expression as vulnerable.

    Published: 8 Dec 2020
    9.8
    Critical

    CVE-2020-28274

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in 'deepref' versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service and may lead to remote code execution.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27918

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Dec 2020
    7.5
    High

    CVE-2020-9991

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iCloud for Windows 7.21, tvOS 14.0. A remote attacker may be able to cause a denial of service.

    Published: 8 Dec 2020
    5.5
    Medium

    CVE-2020-27896

    Last Modified: 21 Nov 2024

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1. A remote attacker may be able to modify the file system.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27930

    Last Modified: 27 Oct 2025

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.

    Published: 8 Dec 2020
    5.5
    Medium

    CVE-2020-27950

    Last Modified: 27 Oct 2025

    A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27932

    Last Modified: 27 Oct 2025

    A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 8 Dec 2020
    5.5
    Medium

    CVE-2020-27929

    Last Modified: 21 Nov 2024

    A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.4.9. A user may send video in Group FaceTime calls without knowing that they have done so.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27917

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to code execution.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27926

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.2 and iPadOS 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27916

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27927

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted font file may lead to arbitrary code execution.

    Published: 8 Dec 2020
    5.5
    Medium

    CVE-2020-27925

    Last Modified: 21 Nov 2024

    An issue existed in the handling of incoming calls. The issue was addressed with additional state checks. This issue is fixed in iOS 14.2 and iPadOS 14.2. A user may answer two calls simultaneously without indication they have answered a second call.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27911

    Last Modified: 21 Nov 2024

    An integer overflow was addressed through improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27912

    Last Modified: 21 Nov 2024

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27909

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 8 Dec 2020
    7.8
    High

    CVE-2020-27910

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 8 Dec 2020