CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-25040

    Last Modified: 21 Nov 2024

    Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.

    Published: 16 Sept 2020
    8.1
    High

    CVE-2020-25039

    Last Modified: 21 Nov 2024

    Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.

    Published: 16 Sept 2020
    6.1
    Medium

    CVE-2020-13928

    Last Modified: 21 Nov 2024

    Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability.

    Published: 16 Sept 2020
    6.5
    Medium

    CVE-2020-25015

    Last Modified: 21 Nov 2024

    A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password.

    Published: 16 Sept 2020
    6.5
    Medium

    CVE-2020-3990

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerability due to an integer overflow issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon Client.

    Published: 16 Sept 2020
    3.3
    Low

    CVE-2020-3989

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to create a partial denial-of-service condition on the system where Workstation or Horizon Client for Windows is installed. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon Client.

    Published: 16 Sept 2020
    6.1
    Medium

    CVE-2020-3988

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (JPEG2000 parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.

    Published: 16 Sept 2020
    6.1
    Medium

    CVE-2020-3987

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.

    Published: 16 Sept 2020
    6.1
    Medium

    CVE-2020-3986

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.

    Published: 16 Sept 2020
    6.7
    Medium

    CVE-2020-3980

    Last Modified: 21 Nov 2024

    VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. An attacker with normal user privileges may exploit this issue to trick an admin user into executing malicious code on the system where Fusion is installed.

    Published: 16 Sept 2020
    5.3
    Medium

    CVE-2020-4708

    Last Modified: 21 Nov 2024

    IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Control-Allow-Origin header. IBM X-Force ID: 187371.

    Published: 16 Sept 2020
    8.2
    High

    CVE-2020-4409

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537.

    Published: 16 Sept 2020
    7.8
    High

    CVE-2020-7532

    Last Modified: 21 Nov 2024

    A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.

    Published: 16 Sept 2020
    7.8
    High

    CVE-2020-7531

    Last Modified: 21 Nov 2024

    A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.

    Published: 16 Sept 2020
    8.8
    High

    CVE-2020-7530

    Last Modified: 21 Nov 2024

    A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.

    Published: 16 Sept 2020
    5.5
    Medium

    CVE-2020-7529

    Last Modified: 21 Nov 2024

    A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.

    Published: 16 Sept 2020
    7.8
    High

    CVE-2020-7528

    Last Modified: 21 Nov 2024

    A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer.

    Published: 16 Sept 2020
    7.3
    High

    CVE-2020-10733

    Last Modified: 21 Nov 2024

    The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.

    Published: 16 Sept 2020
    9.8
    Critical

    CVE-2020-25614

    Last Modified: 21 Nov 2024

    xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.

    Published: 16 Sept 2020
    —
    Unknown

    CVE-2020-24891

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 16 Sept 2020
    9.8
    Critical

    CVE-2020-14315

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.

    Published: 16 Sept 2020
    6.5
    Medium

    CVE-2020-2278

    Last Modified: 21 Nov 2024

    Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with Job/Configure permission to replace any other '.xml' file on the Jenkins controller with a job config.xml file's content.

    Published: 16 Sept 2020
    8.8
    High

    CVE-2020-2276

    Last Modified: 21 Nov 2024

    Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure permission to execute an arbitrary system command on the Jenkins controller as the OS user that the Jenkins process is running as.

    Published: 16 Sept 2020
    6.5
    Medium

    CVE-2020-2277

    Last Modified: 21 Nov 2024

    Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jenkins controller.

    Published: 16 Sept 2020
    4.3
    Medium

    CVE-2020-2273

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 16 Sept 2020
    6.5
    Medium

    CVE-2020-2275

    Last Modified: 21 Nov 2024

    Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.

    Published: 16 Sept 2020
    5.5
    Medium

    CVE-2020-2274

    Last Modified: 21 Nov 2024

    Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2271

    Last Modified: 21 Nov 2024

    Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 16 Sept 2020
    4.3
    Medium

    CVE-2020-2272

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2269

    Last Modified: 21 Nov 2024

    Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to configure views.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2270

    Last Modified: 21 Nov 2024

    Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2266

    Last Modified: 21 Nov 2024

    Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 16 Sept 2020
    4.3
    Medium

    CVE-2020-2267

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to gain access to some metadata of any arbitrary files on the Jenkins controller.

    Published: 16 Sept 2020
    8.8
    High

    CVE-2020-2268

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any arbitrary files on the Jenkins controller.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2264

    Last Modified: 21 Nov 2024

    Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2265

    Last Modified: 21 Nov 2024

    Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2262

    Last Modified: 21 Nov 2024

    Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2263

    Last Modified: 21 Nov 2024

    Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 16 Sept 2020
    4.3
    Medium

    CVE-2020-2260

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.

    Published: 16 Sept 2020
    8.8
    High

    CVE-2020-2261

    Last Modified: 21 Nov 2024

    Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2257

    Last Modified: 21 Nov 2024

    Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 16 Sept 2020
    4.3
    Medium

    CVE-2020-2258

    Last Modified: 21 Nov 2024

    Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2259

    Last Modified: 21 Nov 2024

    Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

    Published: 16 Sept 2020
    5.4
    Medium

    CVE-2020-2256

    Last Modified: 21 Nov 2024

    Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 16 Sept 2020
    4.8
    Medium

    CVE-2020-2253

    Last Modified: 21 Nov 2024

    Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured SMTP server.

    Published: 16 Sept 2020
    4.3
    Medium

    CVE-2020-7268

    Last Modified: 21 Nov 2024

    Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricted directory via external input to construct a path name that should be within a restricted directory.

    Published: 16 Sept 2020
    6.1
    Medium

    CVE-2014-10402

    Last Modified: 21 Nov 2024

    An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.

    Published: 16 Sept 2020
    6.5
    Medium

    CVE-2020-2254

    Last Modified: 21 Nov 2024

    Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.

    Published: 16 Sept 2020
    4.8
    Medium

    CVE-2020-2252

    Last Modified: 21 Nov 2024

    Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.

    Published: 16 Sept 2020
    4.3
    Medium

    CVE-2020-2255

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Blue Ocean Plugin 1.23.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

    Published: 16 Sept 2020