CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2020-8710

    Last Modified: 21 Nov 2024

    Buffer overflow in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    8.2
    High

    CVE-2020-8721

    Last Modified: 21 Nov 2024

    Improper input validation for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    8.2
    High

    CVE-2020-8719

    Last Modified: 21 Nov 2024

    Buffer overflow in subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-8707

    Last Modified: 21 Nov 2024

    Buffer overflow in daemon for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-8731

    Last Modified: 21 Nov 2024

    Incorrect execution-assigned permissions in the file system for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-8730

    Last Modified: 21 Nov 2024

    Heap-based overflow for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    8.8
    High

    CVE-2020-8708

    Last Modified: 21 Nov 2024

    Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Aug 2020
    6.7
    Medium

    CVE-2020-8733

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in the firmware for Intel(R) Server Board M10JNP2SB before version 7.210 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-8736

    Last Modified: 21 Nov 2024

    Improper access control in subsystem for the Intel(R) Computing Improvement Program before version 2.4.5718 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    6.7
    Medium

    CVE-2020-8742

    Last Modified: 21 Nov 2024

    Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-8743

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-8763

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-12287

    Last Modified: 21 Nov 2024

    Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    6.7
    Medium

    CVE-2020-8759

    Last Modified: 21 Nov 2024

    Improper access control in the installer for Intel(R) SSD DCT versions before 3.0.23 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Aug 2020
    4.6
    Medium

    CVE-2019-14630

    Last Modified: 21 Nov 2024

    Reliance on untrusted inputs in a security decision in some Intel(R) Thunderbolt(TM) controllers may allow unauthenticated user to potentially enable information disclosure via physical access.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16290

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16293

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16295

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16300

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16305

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16306

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-24331

    Last Modified: 21 Nov 2024

    An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-24332

    Last Modified: 21 Nov 2024

    An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.

    Published: 13 Aug 2020
    7.5
    High

    CVE-2020-36518

    Last Modified: 27 Aug 2025

    jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

    Published: 13 Aug 2020
    7.3
    High

    CVE-2020-14350

    Last Modified: 21 Nov 2024

    It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16287

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16288

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16291

    Last Modified: 4 Mar 2025

    A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16292

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16296

    Last Modified: 24 Mar 2025

    A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16297

    Last Modified: 14 Mar 2025

    A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16298

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16299

    Last Modified: 21 Nov 2024

    A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16301

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16302

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    7.8
    High

    CVE-2020-16303

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16304

    Last Modified: 14 Mar 2025

    A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16307

    Last Modified: 21 Nov 2024

    A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16308

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16309

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51.

    Published: 13 Aug 2020
    —
    Unknown

    CVE-2020-19500

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 13 Aug 2020
    —
    Unknown

    CVE-2020-20145

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-14834. Reason: This candidate is a reservation duplicate of CVE-2019-14834. Notes: All CVE users should reference CVE-2019-14834 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 13 Aug 2020
    —
    Unknown

    CVE-2020-23255

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 13 Aug 2020
    3.3
    Low

    CVE-2020-29371

    Last Modified: 21 Nov 2024

    An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace, aka CID-bcf85fcedfdd.

    Published: 13 Aug 2020
    6.7
    Medium

    CVE-2021-20292

    Last Modified: 21 Nov 2024

    There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker with a local account with a root privilege, can leverage this vulnerability to escalate privileges and execute code in the context of the kernel.

    Published: 13 Aug 2020
    7.1
    High

    CVE-2020-14349

    Last Modified: 21 Nov 2024

    It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

    Published: 13 Aug 2020
    8
    High

    CVE-2020-14352

    Last Modified: 21 Nov 2024

    A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16289

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16294

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020
    5.5
    Medium

    CVE-2020-16310

    Last Modified: 21 Nov 2024

    A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

    Published: 13 Aug 2020