CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-20032

    Last Modified: 21 Nov 2024

    An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices, may access the system's administration modem.

    Published: 29 Jul 2020
    9.1
    Critical

    CVE-2019-20031

    Last Modified: 21 Nov 2024

    NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks.

    Published: 29 Jul 2020
    7.8
    High

    CVE-2019-20030

    Last Modified: 21 Nov 2024

    An attacker with knowledge of the modem access number on a NEC UM8000 voicemail system may use SSH tunneling or standard Linux utilities to gain access to the system's LAN port. All versions are affected.

    Published: 29 Jul 2020
    8.8
    High

    CVE-2019-20029

    Last Modified: 21 Nov 2024

    An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.

    Published: 29 Jul 2020
    7.5
    High

    CVE-2019-20028

    Last Modified: 21 Nov 2024

    Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice response system content through a system's WebPro administration interface.

    Published: 29 Jul 2020
    9.8
    Critical

    CVE-2019-20027

    Last Modified: 21 Nov 2024

    Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.

    Published: 29 Jul 2020
    7.5
    High

    CVE-2019-20026

    Last Modified: 21 Nov 2024

    The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request.

    Published: 29 Jul 2020
    9.8
    Critical

    CVE-2019-20025

    Last Modified: 21 Nov 2024

    Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with manufacturer privilege level. An attacker could exploit this vulnerability by using this account to remotely log into an affected device. A successful exploit could allow the attacker to log into the device with manufacturer level access. This vulnerability affects SV9100 PBXes that are running software release 6.0 or higher. This vulnerability does not affect SV9100 software releases prior to 6.0.

    Published: 29 Jul 2020
    8.2
    High

    CVE-2020-10713

    Last Modified: 21 Nov 2024

    A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as gaining physical access, obtain the ability to alter a pxe-boot network, or have remote access to a networked system with root access. With this access, an attacker could then craft a string to cause a buffer overflow by injecting a malicious payload that leads to arbitrary code execution within GRUB. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 29 Jul 2020
    6.4
    Medium

    CVE-2020-14308

    Last Modified: 21 Nov 2024

    In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and availability impacts during the boot process.

    Published: 29 Jul 2020
    5.7
    Medium

    CVE-2020-14310

    Last Modified: 21 Nov 2024

    There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.

    Published: 29 Jul 2020
    5.7
    Medium

    CVE-2020-14311

    Last Modified: 21 Nov 2024

    There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.

    Published: 29 Jul 2020
    6.4
    Medium

    CVE-2020-15706

    Last Modified: 21 Nov 2024

    GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

    Published: 29 Jul 2020
    5.7
    Medium

    CVE-2020-15707

    Last Modified: 21 Nov 2024

    Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.

    Published: 29 Jul 2020
    6.7
    Medium

    CVE-2020-14309

    Last Modified: 21 Nov 2024

    There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data.

    Published: 29 Jul 2020
    6.4
    Medium

    CVE-2020-15705

    Last Modified: 21 Nov 2024

    GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

    Published: 29 Jul 2020
    5.9
    Medium

    CVE-2020-11934

    Last Modified: 21 Nov 2024

    It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the system xdg-open. OpenURL() in usersession/userd/launcher.go would alter $XDG_DATA_DIRS to append a path to a directory controlled by the calling snap. A malicious snap could exploit this to bypass intended access restrictions to control how the host system xdg-open script opens the URL and, for example, execute a script shipped with the snap without confinement. This issue did not affect Ubuntu Core systems. Fixed in snapd versions 2.45.1ubuntu0.2, 2.45.1+18.04.2 and 2.45.1+20.04.2.

    Published: 29 Jul 2020
    7.3
    High

    CVE-2020-11933

    Last Modified: 21 Nov 2024

    cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker could exploit by crafting cloud-init user-data/meta-data via external media to perform arbitrary changes on the device to bypass intended security mechanisms such as full disk encryption. This issue did not affect traditional Ubuntu systems. Fixed in snapd version 2.45.2, revision 8539 and core version 2.45.2, revision 9659.

    Published: 29 Jul 2020
    7.7
    High

    CVE-2020-15125

    Last Modified: 21 Nov 2024

    In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0's management API

    Published: 29 Jul 2020
    9.8
    Critical

    CVE-2020-15086

    Last Modified: 21 Nov 2024

    In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to inject arbitrary data having a valid cryptographic message authentication code and can lead to remote code execution. To successfully exploit this vulnerability, an attacker must have access to at least one `Extbase` plugin or module action in a TYPO3 installation. This is fixed in version 7.6.5 of the "mediace" extension for TYPO3.

    Published: 29 Jul 2020
    8.8
    High

    CVE-2020-15098

    Last Modified: 21 Nov 2024

    In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This allows to inject arbitrary data having a valid cryptographic message authentication code (HMAC-SHA1) and can lead to various attack chains including potential privilege escalation, insecure deserialization & remote code execution. The overall severity of this vulnerability is high based on mentioned attack chains and the requirement of having a valid backend user session (authenticated). This has been patched in versions 9.5.20 and 10.4.6.

    Published: 29 Jul 2020
    8.1
    High

    CVE-2020-15099

    Last Modified: 21 Nov 2024

    In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attacker manages to generate a valid cryptographic message authentication code (HMAC-SHA1) - either by using a different existing vulnerability or in case the internal encryptionKey was exposed - it is possible to retrieve arbitrary files of a TYPO3 installation. This includes the possibility to fetch typo3conf/LocalConfiguration.php, which again contains the encryptionKey as well as credentials of the database management system being used. In case a database server is directly accessible either via internet or in a shared hosting network, this allows the ability to completely retrieve, manipulate or delete database contents. This includes creating an administration user account - which can be used to trigger remote code execution by injecting custom extensions. This has been patched in versions 9.5.20 and 10.4.6.

    Published: 29 Jul 2020
    8.8
    High

    CVE-2020-13699

    Last Modified: 21 Nov 2024

    TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.258873, 11.0.258870, 12.0.258869, 13.2.36220, 14.2.56676, 14.7.48350, and 15.8.3.

    Published: 29 Jul 2020
    5.9
    Medium

    CVE-2020-8553

    Last Modified: 21 Nov 2024

    The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.

    Published: 29 Jul 2020
    6.1
    Medium

    CVE-2020-16095

    Last Modified: 21 Nov 2024

    The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS.

    Published: 29 Jul 2020
    5.4
    Medium

    CVE-2020-4645

    Last Modified: 21 Nov 2024

    IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 185717.

    Published: 29 Jul 2020
    5.4
    Medium

    CVE-2020-4644

    Last Modified: 21 Nov 2024

    IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 185716.

    Published: 29 Jul 2020
    7.5
    High

    CVE-2020-4574

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.

    Published: 29 Jul 2020
    5.3
    Medium

    CVE-2020-4573

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated HTTP requests. IBM X-Force ID: 184180.

    Published: 29 Jul 2020
    5.3
    Medium

    CVE-2020-4572

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184179.

    Published: 29 Jul 2020
    6.5
    Medium

    CVE-2020-4569

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism. IBM X-Force ID: 184158.

    Published: 29 Jul 2020
    9.8
    Critical

    CVE-2020-4567

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156.

    Published: 29 Jul 2020
    8.2
    High

    CVE-2020-4463

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.

    Published: 29 Jul 2020
    9.4
    Critical

    CVE-2020-14487

    Last Modified: 21 Nov 2024

    OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands.

    Published: 29 Jul 2020
    6.3
    Medium

    CVE-2020-14486

    Last Modified: 21 Nov 2024

    An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands.

    Published: 29 Jul 2020
    6.5
    Medium

    CVE-2020-2078

    Last Modified: 21 Nov 2024

    Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and gain access to the ftp service. Storing a password in plaintext allows attackers to easily gain access to systems, potentially compromising personal information or other sensitive information.

    Published: 29 Jul 2020
    7.5
    High

    CVE-2020-2077

    Last Modified: 21 Nov 2024

    SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.

    Published: 29 Jul 2020
    9.8
    Critical

    CVE-2020-2076

    Last Modified: 21 Nov 2024

    SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.

    Published: 29 Jul 2020
    8.8
    High

    CVE-2020-14488

    Last Modified: 21 Nov 2024

    OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to upload and execute arbitrary files on the system.

    Published: 29 Jul 2020
    9.8
    Critical

    CVE-2020-7697

    Last Modified: 21 Nov 2024

    This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/getJsonByCurl')(mock2easy, function (error, stdout) { if (error) { return res.json(500, error); } res.json(JSON.parse(stdout)); }, '', _data.interfaceUrl, query, _data.cookie,_data.interfaceType);

    Published: 29 Jul 2020
    8.1
    High

    CVE-2020-7698

    Last Modified: 21 Nov 2024

    This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.

    Published: 29 Jul 2020
    5.4
    Medium

    CVE-2020-14492

    Last Modified: 21 Nov 2024

    OpenClinic GA 5.09.02 and 5.89.05b does not properly neutralize user-controllable input, which may allow the execution of malicious code within the user’s browser.

    Published: 29 Jul 2020
    8.8
    High

    CVE-2020-14493

    Last Modified: 21 Nov 2024

    A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands.

    Published: 29 Jul 2020
    8.8
    High

    CVE-2020-14490

    Last Modified: 21 Nov 2024

    OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files.

    Published: 29 Jul 2020
    6.2
    Medium

    CVE-2020-14489

    Last Modified: 21 Nov 2024

    OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known password cracking techniques.

    Published: 29 Jul 2020
    9.6
    Critical

    CVE-2020-9691

    Last Modified: 21 Nov 2024

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jul 2020
    6.5
    Medium

    CVE-2020-9692

    Last Modified: 21 Nov 2024

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jul 2020
    4.2
    Medium

    CVE-2020-9690

    Last Modified: 21 Nov 2024

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.

    Published: 29 Jul 2020
    6.5
    Medium

    CVE-2020-9689

    Last Modified: 21 Nov 2024

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jul 2020
    5.3
    Medium

    CVE-2020-5614

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 29 Jul 2020