CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-20924

    Last Modified: 21 Nov 2024

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which trigger an invariant in the IndexBoundsBuilder. This issue affects MongoDB Server v4.2 versions prior to 4.2.2.

    Published: 23 Nov 2020
    6.5
    Medium

    CVE-2019-2392

    Last Modified: 21 Nov 2024

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use the $mod operator to overflow negative values. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.1; v4.2 versions prior to 4.2.9; v4.0 versions prior to 4.0.20; v3.6 versions prior to 3.6.20.

    Published: 23 Nov 2020
    6.5
    Medium

    CVE-2019-2393

    Last Modified: 21 Nov 2024

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13 and MongoDB Server v3.6 versions prior to 3.6.15.

    Published: 23 Nov 2020
    5.5
    Medium

    CVE-2020-25677

    Last Modified: 21 Nov 2024

    A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.

    Published: 23 Nov 2020
    7.8
    High

    CVE-2020-27814

    Last Modified: 21 Nov 2024

    A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

    Published: 23 Nov 2020
    6.5
    Medium

    CVE-2020-7928

    Last Modified: 21 Nov 2024

    A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20.

    Published: 23 Nov 2020
    6.5
    Medium

    CVE-2018-20802

    Last Modified: 21 Nov 2024

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting QueryPlanner. This issue affects MongoDB Server v3.6 versions prior to 3.6.9 and MongoDB Server v4.0 versions prior to 4.0.3.

    Published: 23 Nov 2020
    6.5
    Medium

    CVE-2018-20803

    Last Modified: 21 Nov 2024

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects MongoDB Server v4.0 versions prior to 4.0.5; MongoDB Server v3.6 versions prior to 3.6.10 and MongoDB Server v3.4 versions prior to 3.4.19.

    Published: 23 Nov 2020
    7.5
    High

    CVE-2020-7925

    Last Modified: 21 Nov 2024

    Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.

    Published: 23 Nov 2020
    6.5
    Medium

    CVE-2018-20804

    Last Modified: 21 Nov 2024

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects MongoDB Server v4.0 versions prior to 4.0.10 and MongoDB Server v3.6 versions prior to 3.6.13.

    Published: 23 Nov 2020
    5.5
    Medium

    CVE-2021-20284

    Last Modified: 21 Nov 2024

    A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.

    Published: 22 Nov 2020
    7.5
    High

    CVE-2020-14230

    Last Modified: 21 Nov 2024

    HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1 FP10 IF6, 10.0.1 FP5 and 11.0.1 are affected.

    Published: 21 Nov 2020
    7.5
    High

    CVE-2020-14258

    Last Modified: 21 Nov 2024

    HCL Notes is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the client. Versions 9, 10 and 11 are affected.

    Published: 21 Nov 2020
    7.5
    High

    CVE-2020-14234

    Last Modified: 21 Nov 2024

    HCL Domino is susceptible to a Denial of Service vulnerability due to improper validation of user-supplied input, potentially giving an attacker the ability to crash the server. Versions previous to release 9.0.1 FP10 IF6 and release 10.0.1 are affected.

    Published: 21 Nov 2020
    9.8
    Critical

    CVE-2020-25189

    Last Modified: 21 Nov 2024

    The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).

    Published: 21 Nov 2020
    8.8
    High

    CVE-2020-25185

    Last Modified: 21 Nov 2024

    The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).

    Published: 21 Nov 2020
    6.1
    Medium

    CVE-2020-5797

    Last Modified: 21 Nov 2024

    UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network access, to read sensitive files and write to a limited set of files after plugging a crafted USB drive into the router.

    Published: 21 Nov 2020
    5
    Medium

    CVE-2020-25725

    Last Modified: 21 Nov 2024

    In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char in the same Type 3 font.

    Published: 21 Nov 2020
    7.8
    High

    CVE-2021-20294

    Last Modified: 21 Nov 2024

    A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.

    Published: 21 Nov 2020
    7.5
    High

    CVE-2020-28975

    Last Modified: 21 Nov 2024

    svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array. NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute.

    Published: 21 Nov 2020
    8.8
    High

    CVE-2020-35470

    Last Modified: 21 Nov 2024

    Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).

    Published: 21 Nov 2020
    8.2
    High

    CVE-2020-4004

    Last Modified: 31 Oct 2025

    VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

    Published: 20 Nov 2020
    7.8
    High

    CVE-2020-4005

    Last Modified: 31 Oct 2025

    VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG) contains a privilege-escalation vulnerability that exists in the way certain system calls are being managed. A malicious actor with privileges within the VMX process only, may escalate their privileges on the affected system. Successful exploitation of this issue is only possible when chained with another vulnerability (e.g. CVE-2020-4004)

    Published: 20 Nov 2020
    7.8
    High

    CVE-2020-28845

    Last Modified: 21 Nov 2024

    A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.

    Published: 20 Nov 2020
    7.8
    High

    CVE-2020-20740

    Last Modified: 21 Nov 2024

    PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().

    Published: 20 Nov 2020
    5.3
    Medium

    CVE-2020-20739

    Last Modified: 21 Nov 2024

    im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.

    Published: 20 Nov 2020
    7.5
    High

    CVE-2020-26236

    Last Modified: 21 Nov 2024

    In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's account on any site that uses ScratchVerifier for logins. A possible exploitation would follow these steps: 1. User starts login process. 2. Attacker attempts login for user, and is given the same verification code. 3. User comments code as part of their normal login. 4. Before user can, attacker completes the login process now that the code is commented. 5. User gets a failed login and attacker now has control of the account. Since commit a603769 starting a login twice will generate different verification codes, causing both user and attacker login to fail. For clients that rely on a clone of ScratchVerifier not hosted by the developers, their users may attempt to finish the login process as soon as possible after commenting the code. There is no reliable way for the attacker to know before the user can finish the process that the user has commented the code, so this vulnerability only really affects those who comment the code and then take several seconds before finishing the login.

    Published: 20 Nov 2020
    9.8
    Critical

    CVE-2020-28877

    Last Modified: 21 Nov 2024

    Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, including WDR7400, WDR7500, WDR7660, WDR7800, WDR8400, WDR8500, WDR8600, WDR8620, WDR8640, WDR8660, WR880N, WR886N, WR890N, WR890N, WR882N, and WR708N.

    Published: 20 Nov 2020
    8.8
    High

    CVE-2020-13671

    Last Modified: 3 Nov 2025

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

    Published: 20 Nov 2020
    6.5
    Medium

    CVE-2020-19668

    Last Modified: 24 Apr 2026

    Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.

    Published: 20 Nov 2020
    6.4
    Medium

    CVE-2020-7842

    Last Modified: 21 Nov 2024

    Improper Input validation vulnerability exists in Netis Korea D'live AP which could cause arbitrary command injection and execution when the time setting (using ntpServerlp1 parameter) for the users. This affects D'live set-top box AP(WF2429TB) v1.1.10.

    Published: 20 Nov 2020
    9.8
    Critical

    CVE-2020-25839

    Last Modified: 21 Nov 2024

    NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1.

    Published: 20 Nov 2020
    7.5
    High

    CVE-2020-4937

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 191814.

    Published: 20 Nov 2020
    7.8
    High

    CVE-2020-4739

    Last Modified: 21 Nov 2024

    IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 188149.

    Published: 20 Nov 2020
    7.5
    High

    CVE-2020-5668

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/120 (EN) CPU firmware version '51' and earlier, R08/16/32/120SFCPU firmware version '22' and earlier, R08/16/32/120PCPU firmware version '25' and earlier, R08/16/32/120PSFCPU firmware version '06' and earlier, RJ71EN71 firmware version '47' and earlier, RJ71GF11-T2 firmware version '47' and earlier, RJ72GF15-T2 firmware version '07' and earlier, RJ71GP21-SX firmware version '47' and earlier, RJ71GP21S-SX firmware version '47' and earlier, and RJ71GN11-T2 firmware version '11' and earlier) allows a remote unauthenticated attacker to cause an error in a CPU unit and cause a denial-of-service (DoS) condition in execution of the program and its communication, or to cause a denial-of-service (DoS) condition in communication via the unit by receiving a specially crafted SLMP packet

    Published: 20 Nov 2020
    5.3
    Medium

    CVE-2020-28896

    Last Modified: 21 Nov 2024

    Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.

    Published: 20 Nov 2020
    7.5
    High

    CVE-2020-35471

    Last Modified: 21 Nov 2024

    Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.

    Published: 20 Nov 2020
    4.7
    Medium

    CVE-2020-4788

    Last Modified: 21 Nov 2024

    IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.

    Published: 20 Nov 2020
    7
    High

    CVE-2020-28209

    Last Modified: 28 May 2026

    A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.

    Published: 19 Nov 2020
    4.3
    Medium

    CVE-2020-28953

    Last Modified: 21 Nov 2024

    In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.

    Published: 19 Nov 2020
    5.3
    Medium

    CVE-2020-28954

    Last Modified: 21 Nov 2024

    web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.

    Published: 19 Nov 2020
    4.3
    Medium

    CVE-2020-7568

    Last Modified: 29 May 2026

    A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all references, all versions) that could allow non sensitive information disclosure when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.

    Published: 19 Nov 2020
    5.7
    Medium

    CVE-2020-7567

    Last Modified: 29 May 2026

    A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and broke the encryption keys.

    Published: 19 Nov 2020
    7.3
    High

    CVE-2020-7566

    Last Modified: 29 May 2026

    A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption keys when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.

    Published: 19 Nov 2020
    7.3
    High

    CVE-2020-7565

    Last Modified: 29 May 2026

    A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.

    Published: 19 Nov 2020
    7.8
    High

    CVE-2020-7558

    Last Modified: 21 Nov 2024

    A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

    Published: 19 Nov 2020
    7.8
    High

    CVE-2020-7557

    Last Modified: 21 Nov 2024

    A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

    Published: 19 Nov 2020
    7.8
    High

    CVE-2020-7556

    Last Modified: 21 Nov 2024

    A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

    Published: 19 Nov 2020
    7.8
    High

    CVE-2020-7555

    Last Modified: 21 Nov 2024

    A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

    Published: 19 Nov 2020
    7.8
    High

    CVE-2020-7554

    Last Modified: 21 Nov 2024

    A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

    Published: 19 Nov 2020