CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-12334

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the Intel(R) Advisor tools before version 2020 Update 2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12330

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the Intel(R) Falcon 8+ UAS AscTec Thermal Viewer, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.7
    Medium

    CVE-2020-12323

    Last Modified: 21 Nov 2024

    Improper input validation in the Intel(R) ADAS IE before version ADAS_IE_1.0.766 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-24525

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.7
    Medium

    CVE-2020-12337

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12336

    Last Modified: 21 Nov 2024

    Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12320

    Last Modified: 21 Nov 2024

    Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    8.8
    High

    CVE-2020-27386

    Last Modified: 21 Nov 2024

    An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or the FileManager's rename function (in v1.5.7 and prior) to rename the file to an executable extension (e.g., ASP), and finally executing the file via an HTTP GET request to /<path_to_file>.

    Published: 12 Nov 2020
    5.5
    Medium

    CVE-2020-12316

    Last Modified: 21 Nov 2024

    Insufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosure via local access.

    Published: 12 Nov 2020
    9.8
    Critical

    CVE-2020-12315

    Last Modified: 21 Nov 2024

    Path traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 12 Nov 2020
    6.5
    Medium

    CVE-2020-12308

    Last Modified: 21 Nov 2024

    Improper access control for the Intel(R) Computing Improvement Program before version 2.4.5982 may allow an unprivileged user to potentially enable information disclosure via network access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12307

    Last Modified: 21 Nov 2024

    Improper permissions in some Intel(R) High Definition Audio drivers before version 9.21.00.4561 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12306

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the Intel(R) RealSense(TM) D400 Series Dynamic Calibration Tool before version 2.11, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.5
    Medium

    CVE-2020-12322

    Last Modified: 21 Nov 2024

    Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 12 Nov 2020
    6.5
    Medium

    CVE-2020-12319

    Last Modified: 21 Nov 2024

    Insufficient control flow management in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 12 Nov 2020
    6.5
    Medium

    CVE-2020-12317

    Last Modified: 21 Nov 2024

    Improper buffer restriction in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12318

    Last Modified: 21 Nov 2024

    Protection mechanism failure in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.5
    Medium

    CVE-2020-12314

    Last Modified: 21 Nov 2024

    Improper input validation in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 12 Nov 2020
    5.5
    Medium

    CVE-2020-8767

    Last Modified: 21 Nov 2024

    Uncaught exception in the Intel(R) 50GbE IP Core for Intel(R) Quartus Prime before version 20.2 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 12 Nov 2020
    6.5
    Medium

    CVE-2020-8766

    Last Modified: 21 Nov 2024

    Improper conditions check in the Intel(R) SGX DCAP software before version 1.6 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 12 Nov 2020
    8.8
    High

    CVE-2020-8749

    Last Modified: 21 Nov 2024

    Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 12 Nov 2020
    6.5
    Medium

    CVE-2020-8746

    Last Modified: 21 Nov 2024

    Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 12 Nov 2020
    4.4
    Medium

    CVE-2020-12356

    Last Modified: 21 Nov 2024

    Out-of-bounds read in subsystem in Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 12 Nov 2020
    6.4
    Medium

    CVE-2020-8755

    Last Modified: 21 Nov 2024

    Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 12 Nov 2020
    9.1
    Critical

    CVE-2020-8747

    Last Modified: 21 Nov 2024

    Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.

    Published: 12 Nov 2020
    4.6
    Medium

    CVE-2020-8761

    Last Modified: 21 Nov 2024

    Inadequate encryption strength in subsystem for Intel(R) CSME versions before 13.0.40 and 13.30.10 may allow an unauthenticated user to potentially enable information disclosure via physical access.

    Published: 12 Nov 2020
    7.5
    High

    CVE-2020-8754

    Last Modified: 21 Nov 2024

    Out-of-bounds read in subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 12 Nov 2020
    4.6
    Medium

    CVE-2020-8751

    Last Modified: 21 Nov 2024

    Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, Intel(R) TXE versions before 3.1.80 may allow an unauthenticated user to potentially enable information disclosure via physical access.

    Published: 12 Nov 2020
    6.8
    Medium

    CVE-2020-12355

    Last Modified: 4 Nov 2025

    Authentication bypass by capture-replay in RPMB protocol message authentication subsystem in Intel(R) TXE versions before 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-8760

    Last Modified: 21 Nov 2024

    Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.7
    Medium

    CVE-2020-8756

    Last Modified: 21 Nov 2024

    Improper input validation in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.7
    Medium

    CVE-2020-8757

    Last Modified: 21 Nov 2024

    Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12354

    Last Modified: 21 Nov 2024

    Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12303

    Last Modified: 21 Nov 2024

    Use after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-8750

    Last Modified: 21 Nov 2024

    Use after free in Kernel Mode Driver for Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.8
    Medium

    CVE-2020-8705

    Last Modified: 21 Nov 2024

    Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-8744

    Last Modified: 21 Nov 2024

    Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.8
    Medium

    CVE-2020-8745

    Last Modified: 28 Mar 2025

    Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12304

    Last Modified: 21 Nov 2024

    Improper access control in Installer for Intel(R) DAL SDK before version 2.1 for Windows may allow an authenticated user to potentially enable escalation of privileges via local access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-12297

    Last Modified: 21 Nov 2024

    Improper access control in Installer for Intel(R) CSME Driver for Windows versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.

    Published: 12 Nov 2020
    7.5
    High

    CVE-2020-8753

    Last Modified: 21 Nov 2024

    Out-of-bounds read in DHCP subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 12 Nov 2020
    9.8
    Critical

    CVE-2020-8752

    Last Modified: 21 Nov 2024

    Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow an unauthenticated user to potentially enable escalation of privileges via network access.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-8739

    Last Modified: 21 Nov 2024

    Use of potentially dangerous function in Intel BIOS platform sample code for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.7
    Medium

    CVE-2020-8740

    Last Modified: 21 Nov 2024

    Out of bounds write in Intel BIOS platform sample code for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.7
    Medium

    CVE-2020-8738

    Last Modified: 21 Nov 2024

    Improper conditions check in Intel BIOS platform sample code for some Intel(R) Processors before may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    6.7
    Medium

    CVE-2020-8764

    Last Modified: 21 Nov 2024

    Improper access control in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Nov 2020
    5.3
    Medium

    CVE-2020-28247

    Last Modified: 21 Nov 2024

    The lettre library through 0.10.0-alpha for Rust allows arbitrary sendmail option injection via transport/sendmail/mod.rs.

    Published: 12 Nov 2020
    6.8
    Medium

    CVE-2020-12312

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.2 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 12 Nov 2020
    6.8
    Medium

    CVE-2020-8737

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.1 may allow an unauthenticated user to potentially enable escalation of privilege and/or information disclosure via physical access.

    Published: 12 Nov 2020
    6.7
    Medium

    CVE-2020-8691

    Last Modified: 21 Nov 2024

    A logic issue in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.

    Published: 12 Nov 2020