CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2020-15258

    Last Modified: 21 Nov 2024

    In Wire before 3.20.x, `shell.openExternal` was used without checking the URL. This vulnerability allows an attacker to execute code on the victims machine by sending messages containing links with arbitrary protocols. The victim has to interact with the link and sees the URL that is opened. The issue was patched by implementing a helper function which checks if the URL's protocol is common. If it is common, the URL will be opened externally. If not, the URL will not be opened and a warning appears for the user informing them that a probably insecure URL was blocked from being executed. The issue is patched in Wire 3.20.x. More technical details about exploitation are available in the linked advisory.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-9931

    Last Modified: 21 Nov 2024

    A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6. A remote attacker may cause an unexpected application termination.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-9923

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, watchOS 6.2.8. A malicious application may be able to execute arbitrary code with system privileges.

    Published: 16 Oct 2020
    9.8
    Critical

    CVE-2020-9918

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-9917

    Last Modified: 21 Nov 2024

    This issue was addressed with improved checks. This issue is fixed in iOS 13.6 and iPadOS 13.6. A remote attacker may be able to cause a denial of service.

    Published: 16 Oct 2020
    5.3
    Medium

    CVE-2020-9916

    Last Modified: 21 Nov 2024

    A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-9914

    Last Modified: 21 Nov 2024

    An input validation issue existed in Bluetooth. This issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An attacker in a privileged network position may be able to perform denial of service attack using malformed Bluetooth packets.

    Published: 16 Oct 2020
    5.5
    Medium

    CVE-2020-9913

    Last Modified: 21 Nov 2024

    This issue was addressed with improved data protection. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to leak sensitive user information.

    Published: 16 Oct 2020
    3.3
    Low

    CVE-2020-9912

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.2. A malicious attacker may be able to change the origin of a frame for a download in Safari Reader mode.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-9911

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy.

    Published: 16 Oct 2020
    8.8
    High

    CVE-2020-9910

    Last Modified: 21 Nov 2024

    Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

    Published: 16 Oct 2020
    5.9
    Medium

    CVE-2020-9909

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-9907

    Last Modified: 23 Oct 2025

    A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-9903

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.

    Published: 16 Oct 2020
    7.2
    High

    CVE-2020-4636

    Last Modified: 21 Nov 2024

    IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-4254

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 175560.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-9891

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-9890

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-9889

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-9888

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 16 Oct 2020
    5.5
    Medium

    CVE-2020-9885

    Last Modified: 21 Nov 2024

    An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A user that is removed from an iMessage group could rejoin the group.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-9884

    Last Modified: 21 Nov 2024

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-9878

    Last Modified: 21 Nov 2024

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

    Published: 16 Oct 2020
    8.8
    High

    CVE-2020-9870

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. An attacker with memory write capability may be able to bypass pointer authentication codes and run arbitrary code.

    Published: 16 Oct 2020
    8.6
    High

    CVE-2020-9865

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application may be able to break out of its sandbox.

    Published: 16 Oct 2020
    9.8
    Critical

    CVE-2020-9864

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.6. An application may be able to execute arbitrary code with kernel privileges.

    Published: 16 Oct 2020
    8.7
    High

    CVE-2020-15255

    Last Modified: 21 Nov 2024

    In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-9799

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.6. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-27178

    Last Modified: 21 Nov 2024

    Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.

    Published: 16 Oct 2020
    5.4
    Medium

    CVE-2020-26672

    Last Modified: 21 Nov 2024

    Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.

    Published: 16 Oct 2020
    6.1
    Medium

    CVE-2020-24408

    Last Modified: 21 Nov 2024

    Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.

    Published: 16 Oct 2020
    8.8
    High

    CVE-2020-26682

    Last Modified: 21 Nov 2024

    In libass 0.14.0, the `ass_outline_construct`'s call to `outline_stroke` causes a signed integer overflow.

    Published: 16 Oct 2020
    7.1
    High

    CVE-2020-3991

    Last Modified: 21 Nov 2024

    VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue may allow an attacker to overwrite certain admin privileged files through a symbolic link attack at install time. This will result into a denial-of-service condition on the machine where Horizon Client for Windows is installed.

    Published: 16 Oct 2020
    9.8
    Critical

    CVE-2020-26944

    Last Modified: 21 Nov 2024

    An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely.

    Published: 16 Oct 2020
    6.1
    Medium

    CVE-2020-16270

    Last Modified: 21 Nov 2024

    OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS. Remote Attacker can use discovered vulnerability to inject malicious JavaScript payload to victim’s browsers in context of vulnerable applications. Executed code can be used to steal administrator’s cookies, influence HTML content of targeted application and perform phishing-related attacks. Vulnerable application used in more than 3000 organizations in different sectors from retail to industries.

    Published: 16 Oct 2020
    7.2
    High

    CVE-2020-15867

    Last Modified: 21 Nov 2024

    The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in the documentation but not in the UI, it could be considered a "Product UI does not Warn User of Unsafe Actions" issue.

    Published: 16 Oct 2020
    7.2
    High

    CVE-2020-14144

    Last Modified: 21 Nov 2024

    The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that the dangerousness of this feature should be documented immediately above the ENABLE_GIT_HOOKS line in the config file). NOTE: The vendor has indicated this is not a vulnerability and states "This is a functionality of the software that is limited to a very limited subset of accounts. If you give someone the privilege to execute arbitrary code on your server, they can execute arbitrary code on your server. We provide very clear warnings to users around this functionality and what it provides.

    Published: 16 Oct 2020
    9.1
    Critical

    CVE-2019-19885

    Last Modified: 21 Nov 2024

    In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2020-26893

    Last Modified: 21 Nov 2024

    An issue was discovered in ClamXAV 3 before 3.1.1. A malicious actor could use a properly signed copy of ClamXAV 2 (running with an injected malicious dylib) to communicate with ClamXAV 3's helper tool and perform privileged operations. This occurs because of inadequate client verification in the helper tool.

    Published: 16 Oct 2020
    9.8
    Critical

    CVE-2019-19513

    Last Modified: 21 Nov 2024

    The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability. An attacker may exploit this to execute code on the target machine. A failure in exploitation leads to a denial of service.

    Published: 16 Oct 2020
    6.5
    Medium

    CVE-2019-18796

    Last Modified: 21 Nov 2024

    The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 file. This weakness could allow attackers to consume excessive CPU and the application becomes unresponsive.

    Published: 16 Oct 2020
    6.5
    Medium

    CVE-2019-18795

    Last Modified: 21 Nov 2024

    The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile out of bounds read vulnerability via a crafted .wav file. An attacker can exploit this issues to gain access to sensitive information that may aid in further attacks. A failure in exploitation leads to denial of service.

    Published: 16 Oct 2020
    6.5
    Medium

    CVE-2019-18794

    Last Modified: 21 Nov 2024

    The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can exploit this to gain access to sensitive information that may aid in further attacks. A failure in exploitation leads to denial of service.

    Published: 16 Oct 2020
    9.9
    Critical

    CVE-2020-26943

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Horizon dashboard with the blazar-dashboard plugin are affected.

    Published: 16 Oct 2020
    6.1
    Medium

    CVE-2020-26584

    Last Modified: 21 Nov 2024

    An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog is vulnerable to Reflected XSS. If the attacker can lure a user into clicking a crafted link, he can execute arbitrary JavaScript code in the user's browser. The vulnerability can be used to change the contents of the displayed site, redirect to other sites, or steal user credentials. Additionally, users are potential victims of browser exploits and JavaScript malware.

    Published: 16 Oct 2020
    6.1
    Medium

    CVE-2020-26583

    Last Modified: 21 Nov 2024

    An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses claiming functionality. However, to view the file, authentication is required. By exploiting this vulnerability, an attacker can persistently include arbitrary HTML or JavaScript code into the affected web page. The vulnerability can be used to change the contents of the displayed site, redirect to other sites, or steal user credentials. Additionally, users are potential victims of browser exploits and JavaScript malware.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-25829

    Last Modified: 21 Nov 2024

    An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state, instead of their actual DNSSEC Secure state, via a DNS ANY query. This results in a denial of service for installation that always validate (dnssec=validate), and for clients requesting validation when on-demand validation is enabled (dnssec=process).

    Published: 16 Oct 2020
    8.3
    High

    CVE-2020-27176

    Last Modified: 21 Nov 2024

    Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HTML even though HTML support is not one of the primary advertised roles of the product.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-27174

    Last Modified: 21 Nov 2024

    In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-27173

    Last Modified: 21 Nov 2024

    In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). This behavior cannot be reproduced from the guest side. When no rate limiting is in place, the host can be subject to memory pressure, impacting all other VMs running on the same host.

    Published: 16 Oct 2020