CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-4452

    Last Modified: 21 Nov 2024

    A memory consumption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.3, Security Update 2019-001 High Sierra, Security Update 2019-001 Sierra, macOS Mojave 10.14.2, Security Update 2018-003 High Sierra, Security Update 2018-006 Sierra. A malicious application may be able to execute arbitrary code with system privileges.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2018-4468

    Last Modified: 21 Nov 2024

    This issue was addressed by removing additional entitlements. This issue is fixed in macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra. A malicious application may be able to access restricted files.

    Published: 27 Oct 2020
    7.8
    High

    CVE-2018-4451

    Last Modified: 21 Nov 2024

    This issue is fixed in macOS Mojave 10.14. A memory corruption issue was addressed with improved input validation.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2018-4433

    Last Modified: 21 Nov 2024

    A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, watchOS 5, iOS 12, tvOS 12, macOS Mojave 10.14. A malicious application may be able to modify protected parts of the file system.

    Published: 27 Oct 2020
    6.5
    Medium

    CVE-2018-4444

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2018-4391

    Last Modified: 21 Nov 2024

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may lead to UI spoofing.

    Published: 27 Oct 2020
    7.1
    High

    CVE-2018-4428

    Last Modified: 21 Nov 2024

    A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 12.1.1. A local attacker may be able to share items from the lock screen.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2018-4381

    Last Modified: 21 Nov 2024

    A resource exhaustion issue was addressed with improved input validation. This issue is fixed in tvOS 12.1, iOS 12.1. Processing a maliciously crafted message may lead to a denial of service.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2018-4390

    Last Modified: 21 Nov 2024

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may lead to UI spoofing.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2018-4339

    Last Modified: 21 Nov 2024

    This issue was addressed with a new entitlement. This issue is fixed in iOS 12.1. A local user may be able to read a persistent device identifier.

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2018-4296

    Last Modified: 21 Nov 2024

    This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks.

    Published: 27 Oct 2020
    7.1
    High

    CVE-2020-15238

    Last Modified: 21 Nov 2024

    Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argument injection vulnerability. The impact highly depends on the system configuration. If Polkit-1 is disabled and for versions lower than 2.0.6, any local user can possibly exploit this. If Polkit-1 is enabled for version 2.0.6 and later, a possible attacker needs to be allowed to use the `org.blueman.dhcp.client` action. That is limited to users in the wheel group in the shipped rules file that do have the privileges anyway. On systems with ISC DHCP client (dhclient), attackers can pass arguments to `ip link` with the interface name that can e.g. be used to bring down an interface or add an arbitrary XDP/BPF program. On systems with dhcpcd and without ISC DHCP client, attackers can even run arbitrary scripts by passing `-c/path/to/script` as an interface name. Patches are included in 2.1.4 and master that change the DhcpClient D-Bus method(s) to accept BlueZ network object paths instead of network interface names. A backport to 2.0(.8) is also available. As a workaround, make sure that Polkit-1-support is enabled and limit privileges for the `org.blueman.dhcp.client` action to users that are able to run arbitrary commands as root anyway in /usr/share/polkit-1/rules.d/blueman.rules.

    Published: 27 Oct 2020
    —
    Unknown

    CVE-2020-26156

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2020-27853

    Last Modified: 21 Nov 2024

    Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a format string. This affects Wire AVS (Audio, Video, and Signaling) 5.3 through 6.x before 6.4, the Wire Secure Messenger application before 3.49.918 for Android, and the Wire Secure Messenger application before 3.61 for iOS. This occurs via the value parameter to sdp_media_set_lattr in peerflow/sdp.c.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-7755

    Last Modified: 7 Jan 2025

    All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values.

    Published: 27 Oct 2020
    7.8
    High

    CVE-2020-11858

    Last Modified: 21 Nov 2024

    Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Bridge (containerized). The vulneravility affects: 1.) Operation Bridge Manager versions: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) versions: 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. The vulnerability could allow local attackers to execute code with escalated privileges.

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2020-11854

    Last Modified: 21 Nov 2024

    Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Performance Management versions 9,51, 9.50 and 9.40 with uCMDB 10.33 CUP 3. The vulnerability could allow Arbitrary code execution.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-23945

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database.

    Published: 27 Oct 2020
    7.8
    High

    CVE-2020-6023

    Last Modified: 21 Nov 2024

    Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2020-6022

    Last Modified: 21 Nov 2024

    Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-8579

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an attacker with access to an intercluster LIF to cause a Denial of Service (DoS).

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2020-10256

    Last Modified: 21 Nov 2024

    An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption.

    Published: 27 Oct 2020
    7.8
    High

    CVE-2020-23864

    Last Modified: 21 Nov 2024

    An issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a malicious DLL file into the WindowsApps folder.

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2020-27179

    Last Modified: 21 Nov 2024

    konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2020-27183

    Last Modified: 21 Nov 2024

    A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges of arbitrary user accounts, and have unspecified other impact.

    Published: 27 Oct 2020
    6.1
    Medium

    CVE-2020-27182

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, ixedit/editor_component.jsp, or the login form.

    Published: 27 Oct 2020
    6.5
    Medium

    CVE-2020-27181

    Last Modified: 21 Nov 2024

    A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-27180

    Last Modified: 21 Nov 2024

    konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.

    Published: 27 Oct 2020
    3.3
    Low

    CVE-2020-8956

    Last Modified: 21 Nov 2024

    Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.

    Published: 27 Oct 2020
    7.2
    High

    CVE-2020-15352

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

    Published: 27 Oct 2020
    5.5
    Medium

    CVE-2018-21269

    Last Modified: 21 Nov 2024

    checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink.

    Published: 27 Oct 2020
    —
    Unknown

    CVE-2020-27834

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 27 Oct 2020
    7.2
    High

    CVE-2020-25654

    Last Modified: 21 Nov 2024

    An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2020-27780

    Last Modified: 21 Nov 2024

    A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.

    Published: 27 Oct 2020
    7.5
    High

    CVE-2020-7753

    Last Modified: 21 Nov 2024

    All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().

    Published: 27 Oct 2020
    9.8
    Critical

    CVE-2020-27743

    Last Modified: 21 Nov 2024

    libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.

    Published: 26 Oct 2020
    7.5
    High

    CVE-2020-1915

    Last Modified: 21 Nov 2024

    An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

    Published: 26 Oct 2020
    9.8
    Critical

    CVE-2020-26879

    Last Modified: 21 Nov 2024

    Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.

    Published: 26 Oct 2020
    8.8
    High

    CVE-2020-26878

    Last Modified: 21 Nov 2024

    Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.

    Published: 26 Oct 2020
    6.5
    Medium

    CVE-2020-25034

    Last Modified: 21 Nov 2024

    eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature.

    Published: 26 Oct 2020
    5.8
    Medium

    CVE-2020-15274

    Last Modified: 21 Nov 2024

    In Wiki.js before version 2.5.162, an XSS payload can be injected in a page title and executed via the search results. While the title is properly escaped in both the navigation links and the actual page title, it is not the case in the search results. Commit a57d9af34c15adbf460dde6553d964efddf433de fixes this vulnerability (version 2.5.162) by properly escaping the text content displayed in the search results.

    Published: 26 Oct 2020
    8.7
    High

    CVE-2020-15272

    Last Modified: 21 Nov 2024

    In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has been patched in version 1.0.1. If you don't use the `tag` input you are most likely safe. The `GITHUB_REF` environment variable is protected by the GitHub Actions environment so attacks from there should be impossible. If you must use the `tag` input and cannot upgrade to `> 1.0.0` make sure that the value is not controlled by another Action.

    Published: 26 Oct 2020
    9.3
    Critical

    CVE-2020-15271

    Last Modified: 21 Nov 2024

    In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on their system. This is fixed in version 2.3.0. As a workaround, the `lookatme/contrib/terminal.py` and `lookatme/contrib/file_loader.py` files may be manually deleted. Additionally, it is always recommended to be aware of what is being rendered with lookatme.

    Published: 26 Oct 2020
    5.5
    Medium

    CVE-2017-18925

    Last Modified: 21 Nov 2024

    opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.

    Published: 26 Oct 2020
    7.5
    High

    CVE-2020-26566

    Last Modified: 21 Nov 2024

    A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a webu.c segmentation fault and kill the main process via a crafted HTTP request.

    Published: 26 Oct 2020
    6.1
    Medium

    CVE-2020-26161

    Last Modified: 21 Nov 2024

    In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

    Published: 26 Oct 2020
    8.8
    High

    CVE-2020-7752

    Last Modified: 21 Nov 2024

    This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.

    Published: 26 Oct 2020
    7.8
    High

    CVE-2020-27187

    Last Modified: 21 Nov 2024

    An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service invoking D-Bus is not properly checked. An attacker on the local machine can replace /etc/fstab, and execute mount and other partitioning related commands, while KDE Partition Manager is running. the mount command can then be used to gain full root privileges.

    Published: 26 Oct 2020
    5.4
    Medium

    CVE-2020-6876

    Last Modified: 21 Nov 2024

    A ZTE product is impacted by an XSS vulnerability. The vulnerability is caused by the lack of correct verification of client data in the WEB module. By inserting malicious scripts into the web module, a remote attacker could trigger an XSS attack when the user browses the web page. Then the attacker could use the vulnerability to steal user cookies or destroy the page structure. This affects: eVDC ZXCLOUD-iROSV6.03.04

    Published: 26 Oct 2020
    9.6
    Critical

    CVE-2020-18766

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.

    Published: 26 Oct 2020