CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-9871

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 22 Oct 2020
    9.1
    Critical

    CVE-2020-9868

    Last Modified: 21 Nov 2024

    A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been able to impersonate a trusted website using shared key material for an administrator added certificate.

    Published: 22 Oct 2020
    7.8
    High

    CVE-2020-9863

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An application may be able to execute arbitrary code with kernel privileges.

    Published: 22 Oct 2020
    7.5
    High

    CVE-2020-9869

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. A remote attacker may cause an unexpected application termination.

    Published: 22 Oct 2020
    7.8
    High

    CVE-2020-9854

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5. An application may be able to gain elevated privileges.

    Published: 22 Oct 2020
    7.5
    High

    CVE-2020-9828

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to leak sensitive user information.

    Published: 22 Oct 2020
    7.8
    High

    CVE-2020-9853

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to determine kernel memory layout.

    Published: 22 Oct 2020
    5.5
    Medium

    CVE-2020-9772

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A sandboxed process may be able to circumvent sandbox restrictions.

    Published: 22 Oct 2020
    5.3
    Medium

    CVE-2020-9787

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. Some websites may not have appeared in Safari Preferences.

    Published: 22 Oct 2020
    7
    High

    CVE-2020-9796

    Last Modified: 21 Nov 2024

    A race condition was addressed with improved state handling. This issue is fixed in macOS Catalina 10.15.5. An application may be able to execute arbitrary code with kernel privileges.

    Published: 22 Oct 2020
    7.1
    High

    CVE-2020-9771

    Last Modified: 21 Nov 2024

    This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A user may gain access to protected parts of the file system.

    Published: 22 Oct 2020
    6.8
    Medium

    CVE-2020-9810

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A person with physical access to a Mac may be able to bypass Login Window.

    Published: 22 Oct 2020
    7.1
    High

    CVE-2020-9779

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.

    Published: 22 Oct 2020
    5.5
    Medium

    CVE-2020-3918

    Last Modified: 21 Nov 2024

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A local user may be able to view sensitive user information.

    Published: 22 Oct 2020
    7.8
    High

    CVE-2020-3915

    Last Modified: 21 Nov 2024

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to overwrite arbitrary files.

    Published: 22 Oct 2020
    9.8
    Critical

    CVE-2020-15906

    Last Modified: 21 Nov 2024

    tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

    Published: 22 Oct 2020
    7.5
    High

    CVE-2020-27155

    Last Modified: 21 Nov 2024

    An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one.

    Published: 22 Oct 2020
    5.4
    Medium

    CVE-2020-27533

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.

    Published: 22 Oct 2020
    5.3
    Medium

    CVE-2020-26650

    Last Modified: 21 Nov 2024

    AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php

    Published: 22 Oct 2020
    8.1
    High

    CVE-2020-26649

    Last Modified: 21 Nov 2024

    AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php

    Published: 22 Oct 2020
    4.4
    Medium

    CVE-2021-20177

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can panic the system. Kernel before kernel 5.5-rc1 is affected.

    Published: 22 Oct 2020
    8.8
    High

    CVE-2020-24033

    Last Modified: 21 Nov 2024

    An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escalated privileges.

    Published: 22 Oct 2020
    6.5
    Medium

    CVE-2020-27646

    Last Modified: 21 Nov 2024

    Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft.

    Published: 22 Oct 2020
    6.1
    Medium

    CVE-2020-27642

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.

    Published: 22 Oct 2020
    7.5
    High

    CVE-2020-27638

    Last Modified: 21 Nov 2024

    receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.

    Published: 22 Oct 2020
    6.1
    Medium

    CVE-2020-27620

    Last Modified: 21 Nov 2024

    The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.

    Published: 22 Oct 2020
    4.3
    Medium

    CVE-2020-27621

    Last Modified: 21 Nov 2024

    The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.

    Published: 22 Oct 2020
    7
    High

    CVE-2020-27216

    Last Modified: 21 Nov 2024

    In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0049

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0068

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0087

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0150

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0191

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    5.7
    Medium

    CVE-2020-25655

    Last Modified: 21 Nov 2024

    An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0010

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0011

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0014

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0015

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0016

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0017

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0018

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0019

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0020

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0021

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0022

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0024

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0025

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0026

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0027

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2021-0028

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none.

    Published: 22 Oct 2020