CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2020-15151

    Last Modified: 21 Nov 2024

    OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2.

    Published: 19 Aug 2020
    9.9
    Critical

    CVE-2020-15149

    Last Modified: 21 Nov 2024

    NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation event due via an account takeover. As a workaround you may cherry-pick the following commit from the project's repository to your running instance of NodeBB: 16cee1b03ba3eee177834a1fdac4aa8a12b39d2a. This is fixed in version 1.14.3.

    Published: 19 Aug 2020
    6
    Medium

    CVE-2020-14367

    Last Modified: 21 Nov 2024

    A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged access to create a symlink with the default PID file name pointing to any destination file in the system, resulting in data loss and a denial of service due to the path traversal.

    Published: 19 Aug 2020
    6.5
    Medium

    CVE-2020-23574

    Last Modified: 21 Nov 2024

    When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This will create a buffer overflow condition, causing the application to crash.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-11848

    Last Modified: 21 Nov 2024

    Denial of service vulnerability on Micro Focus ArcSight Management Center. Affecting all versions prior to version 2.9.5. The vulnerability could cause the server to become unavailable, causing a denial of service.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-24368

    Last Modified: 21 Nov 2024

    Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9724

    Last Modified: 21 Nov 2024

    Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability. Successful exploitation could lead to privilege escalation.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-9723

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9722

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-9721

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-9720

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-9719

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-9718

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-9717

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-9716

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9714

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation .

    Published: 19 Aug 2020
    5.5
    Medium

    CVE-2020-9712

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.

    Published: 19 Aug 2020
    3.3
    Low

    CVE-2020-9710

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    5.5
    Medium

    CVE-2020-9697

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a disclosure of sensitive data vulnerability. Successful exploitation could lead to memory leak.

    Published: 19 Aug 2020
    5.5
    Medium

    CVE-2020-9696

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9694

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9693

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Aug 2020
    3.3
    Low

    CVE-2020-9707

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    3.3
    Low

    CVE-2020-9706

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-9705

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9704

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Aug 2020
    5.5
    Medium

    CVE-2020-9703

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to application denial-of-service.

    Published: 19 Aug 2020
    5.5
    Medium

    CVE-2020-9702

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to application denial-of-service.

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9701

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9700

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9699

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9698

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Aug 2020
    6.1
    Medium

    CVE-2020-4653

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

    Published: 19 Aug 2020
    6.5
    Medium

    CVE-2020-4648

    Last Modified: 21 Nov 2024

    A vulnerability exsists in IBM Planning Analytics 2.0 whereby avatars in Planning Analytics Workspace could be modified by other users without authorization to do so. IBM X-Force ID: 186019.

    Published: 19 Aug 2020
    6.5
    Medium

    CVE-2020-4381

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denial of service during deployment or upgrade if GUI specific services are enabled. IBM X-Force ID: 179162.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-24381

    Last Modified: 21 Nov 2024

    GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.

    Published: 19 Aug 2020
    7.8
    High

    CVE-2020-9715

    Last Modified: 14 Apr 2026

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24459

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24469

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24477

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24483

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24517

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24526

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24536

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020
    8.8
    High

    CVE-2020-24870

    Last Modified: 21 Nov 2024

    Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2020-8231

    Last Modified: 21 Nov 2024

    Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

    Published: 19 Aug 2020
    7.5
    High

    CVE-2021-29482

    Last Modified: 21 Nov 2024

    xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. The problem has been fixed in release v0.5.8. As a workaround users can limit the size of the compressed file input to a reasonable size for their use case. The standard library had recently the same issue and got the CVE-2020-16845 allocated.

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24449

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24461

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020
    —
    Unknown

    CVE-2020-24463

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 19 Aug 2020