CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-8241

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.

    Published: 28 Oct 2020
    4.9
    Medium

    CVE-2020-8255

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.

    Published: 28 Oct 2020
    9.8
    Critical

    CVE-2020-8239

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.

    Published: 28 Oct 2020
    8.8
    High

    CVE-2020-8254

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affects Windows PDC.To improve the security of connections between Pulse clients and Pulse Connect Secure, see below recommendation(s):Disable Dynamic certificate trust for PDC.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-8240

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-8250

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-8249

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-8248

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.

    Published: 28 Oct 2020
    7.5
    High

    CVE-2021-26118

    Last Modified: 15 Jun 2026

    While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-5144

    Last Modified: 21 Nov 2024

    SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability.

    Published: 28 Oct 2020
    8.6
    High

    CVE-2020-5145

    Last Modified: 21 Nov 2024

    SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execution in the target system.

    Published: 28 Oct 2020
    5.4
    Medium

    CVE-2020-27957

    Last Modified: 21 Nov 2024

    The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.

    Published: 28 Oct 2020
    9.8
    Critical

    CVE-2020-27956

    Last Modified: 21 Nov 2024

    An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-26131

    Last Modified: 21 Nov 2024

    Issues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the OpenDHCPServer.exe (Regular) or the OpenDHCPLdap.exe (LDAP Based) binary.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-26132

    Last Modified: 21 Nov 2024

    An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the HomeDNSServer.exe binary.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-26133

    Last Modified: 21 Nov 2024

    An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the DualServer.exe binary.

    Published: 28 Oct 2020
    7.5
    High

    CVE-2020-36317

    Last Modified: 21 Nov 2024

    In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could result in a memory safety violation when other string APIs assume that UTF-8 encoding is used on the same string.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-26130

    Last Modified: 21 Nov 2024

    Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the OpenTFTPServerMT.exe or the OpenTFTPServerSP.exe binary.

    Published: 28 Oct 2020
    6.1
    Medium

    CVE-2020-16140

    Last Modified: 21 Nov 2024

    The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.

    Published: 27 Oct 2020
    5.3
    Medium

    CVE-2019-8796

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, iOS 12.4.3, watchOS 6.1, iOS 13.2 and iPadOS 13.2. AirDrop transfers may be unexpectedly accepted while in Everyone mode.

    Published: 27 Oct 2020
    6.5
    Medium

    CVE-2019-8664

    Last Modified: 21 Nov 2024

    An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2019-8531

    Last Modified: 21 Nov 2024

    A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An untrusted radius server certificate may be trusted.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2020-9982

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Apple Music 3.4.0 for Android. A malicious application may be able to leak a user's credentials.

    Published: 27 Oct 2020
    7.8
    High

    CVE-2020-9973

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-9941

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to unexpectedly alter application state.

    Published: 27 Oct 2020
    8.8
    High

    CVE-2020-9932

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, tvOS 13. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2020-9979

    Last Modified: 21 Nov 2024

    A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An attacker may be able to misuse a trust relationship to download malicious content.

    Published: 27 Oct 2020
    4.3
    Medium

    CVE-2020-9857

    Last Modified: 21 Nov 2024

    An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5, Security Update 2020-003 Mojave, Security Update 2020-003 High Sierra. A malicious website may be able to exfiltrate autofilled data in Safari.

    Published: 27 Oct 2020
    7.8
    High

    CVE-2020-3880

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-9782

    Last Modified: 21 Nov 2024

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A remote attacker may be able to overwrite existing files.

    Published: 27 Oct 2020
    7.8
    High

    CVE-2020-9961

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 27 Oct 2020
    7.8
    High

    CVE-2020-3863

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. An application may be able to execute arbitrary code with system privileges.

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2020-9866

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. A buffer overflow may result in arbitrary code execution.

    Published: 27 Oct 2020
    5.4
    Medium

    CVE-2020-9860

    Last Modified: 21 Nov 2024

    A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 13.0.5. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.

    Published: 27 Oct 2020
    3.3
    Low

    CVE-2020-9786

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. An application may be able to trigger a sysdiagnose.

    Published: 27 Oct 2020
    7.8
    High

    CVE-2020-3851

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. An application may be able to gain elevated privileges.

    Published: 27 Oct 2020
    8.2
    High

    CVE-2020-27890

    Last Modified: 21 Nov 2024

    The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Write Attributes No Response message. It crashes in zclParseInWriteCmd() and does not update the specific attribute's value.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-27891

    Last Modified: 21 Nov 2024

    The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Read Reporting Configuration Response message. It crashes in zclHandleExternal().

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-27892

    Last Modified: 21 Nov 2024

    The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Discover Commands Received Response message or a ZCL Discover Commands Generated Response message. It crashes in zclParseInDiscCmdsRspCmd().

    Published: 27 Oct 2020
    7.1
    High

    CVE-2020-3855

    Last Modified: 21 Nov 2024

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. A malicious application may be able to overwrite arbitrary files.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-9774

    Last Modified: 21 Nov 2024

    An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting access to encrypted data. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Encrypted data may be inappropriately accessed.

    Published: 27 Oct 2020
    5.3
    Medium

    CVE-2019-8858

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. A user who shares their screen may not be able to end screen sharing.

    Published: 27 Oct 2020
    6.3
    Medium

    CVE-2019-8855

    Last Modified: 21 Nov 2024

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to access restricted files.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2019-8854

    Last Modified: 21 Nov 2024

    A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. A device may be passively tracked by its Wi-Fi MAC address.

    Published: 27 Oct 2020
    5.3
    Medium

    CVE-2020-3852

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrectly ignored when determining multimedia permission for a website.

    Published: 27 Oct 2020
    4.3
    Medium

    CVE-2019-8898

    Last Modified: 21 Nov 2024

    An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.

    Published: 27 Oct 2020
    6.5
    Medium

    CVE-2019-8901

    Last Modified: 21 Nov 2024

    This issue was addressed by verifying host keys when connecting to a previously-known SSH server. This issue is fixed in iOS 13.1 and iPadOS 13.1. An attacker in a privileged network position may be able to intercept SSH traffic from the “Run script over SSH” action.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2019-8853

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to read restricted memory.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2019-8850

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13.1 and iPadOS 13.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6. Processing a maliciously crafted audio file may disclose restricted memory.

    Published: 27 Oct 2020
    3.3
    Low

    CVE-2019-8857

    Last Modified: 21 Nov 2024

    The issue was addressed with improved validation when an iCloud Link is created. This issue is fixed in iOS 13.3 and iPadOS 13.3. Live Photo audio and video data may be shared via iCloud links even if Live Photo is disabled in the Share Sheet carousel.

    Published: 27 Oct 2020