CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-15658

    Last Modified: 21 Nov 2024

    The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

    Published: 28 Jul 2020
    5.5
    Medium

    CVE-2020-24240

    Last Modified: 21 Nov 2024

    GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.

    Published: 28 Jul 2020
    9.9
    Critical

    CVE-2020-10731

    Last Modified: 21 Nov 2024

    A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all running virtual machines.

    Published: 28 Jul 2020
    5.5
    Medium

    CVE-2020-15650

    Last Modified: 21 Nov 2024

    Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.

    Published: 28 Jul 2020
    6.5
    Medium

    CVE-2020-15655

    Last Modified: 21 Nov 2024

    A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

    Published: 28 Jul 2020
    8.8
    High

    CVE-2020-15656

    Last Modified: 21 Nov 2024

    JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

    Published: 28 Jul 2020
    5.5
    Medium

    CVE-2020-24241

    Last Modified: 21 Nov 2024

    In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.

    Published: 28 Jul 2020
    5.5
    Medium

    CVE-2020-24242

    Last Modified: 21 Nov 2024

    In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.

    Published: 28 Jul 2020
    6.6
    Medium

    CVE-2020-14331

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA console to crash the system, potentially escalating their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 28 Jul 2020
    6.5
    Medium

    CVE-2020-15653

    Last Modified: 21 Nov 2024

    An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

    Published: 28 Jul 2020
    7.8
    High

    CVE-2020-15657

    Last Modified: 21 Nov 2024

    Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

    Published: 28 Jul 2020
    8.8
    High

    CVE-2020-15659

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.

    Published: 28 Jul 2020
    7.5
    High

    CVE-2020-12845

    Last Modified: 21 Nov 2024

    Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed Authorization header that is mishandled during a cherokee_buffer_add call within cherokee_validator_parse_basic or cherokee_validator_parse_digest.

    Published: 27 Jul 2020
    9.8
    Critical

    CVE-2020-12460

    Last Modified: 21 Nov 2024

    OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its PREV_INUSE flag.

    Published: 27 Jul 2020
    5.5
    Medium

    CVE-2020-12880

    Last Modified: 21 Nov 2024

    An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)

    Published: 27 Jul 2020
    6.5
    Medium

    CVE-2020-10643

    Last Modified: 21 Nov 2024

    An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vulnerable web page due to a known issue in a third-party component.

    Published: 27 Jul 2020
    7.5
    High

    CVE-2020-10609

    Last Modified: 21 Nov 2024

    Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modification to system settings by someone with access to the device.

    Published: 27 Jul 2020
    7.8
    High

    CVE-2020-1457

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1425.

    Published: 27 Jul 2020
    7.8
    High

    CVE-2020-1425

    Last Modified: 21 Nov 2024

    A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1457.

    Published: 27 Jul 2020
    4.9
    Medium

    CVE-2020-15120

    Last Modified: 21 Nov 2024

    In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another project, without knowledge of this other project's private code. This can be further exploited to access all bills of another project without knowledge of this other project's private code. With the default configuration, anybody is allowed to create a new project. An attacker can create a new project and then use it to become authenticated and exploit this flaw. As such, the exposure is similar to an unauthenticated attack, because it is trivial to become authenticated. This is fixed in version 4.1.5.

    Published: 27 Jul 2020
    7.8
    High

    CVE-2020-15593

    Last Modified: 21 Nov 2024

    SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among different processes and uses IPC (Inter-Process Communication) primitives to enable the processes to cooperate. Any user in the system is allowed to access the interprocess communication channel AternityAgentAssistantIpc, retrieve a serialized object and call object methods remotely. Among others, the methods allow any user to: (1) Create and/or overwrite arbitrary XML files across the system; (2) Create arbitrary directories across the system; and (3) Load arbitrary plugins (i.e., C# assemblies) from the "%PROGRAMFILES(X86)/Aternity Information Systems/Assistant/plugins” directory and execute code contained in them.

    Published: 27 Jul 2020
    7.5
    High

    CVE-2020-15592

    Last Modified: 21 Nov 2024

    SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among different processes and uses IPC (Inter-Process Communication) primitives to enable the processes to cooperate. The remotely callable methods from remotable objects available through interprocess communication allow loading of arbitrary plugins (i.e., C# assemblies) from the "%PROGRAMFILES(X86)%/Aternity Information Systems/Assistant/plugins” directory, where the name of the plugin is passed as part of an XML-serialized object. However, because the name of the DLL is concatenated with the “.\plugins” string, a directory traversal vulnerability exists in the way plugins are resolved.

    Published: 27 Jul 2020
    4.4
    Medium

    CVE-2020-4498

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.1 LTS and 9.1 CD could allow a local privileged user to obtain highly sensitve information due to inclusion of data within trace files. IBM X-Force ID: 182118.

    Published: 27 Jul 2020
    4.6
    Medium

    CVE-2020-4408

    Last Modified: 21 Nov 2024

    The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords during input, which could be obtained by a physical attacker nearby. IBM X-Force ID: 179536.

    Published: 27 Jul 2020
    4.3
    Medium

    CVE-2020-4405

    Last Modified: 21 Nov 2024

    IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due to world readable log files. IBM X-Force ID: 179484.

    Published: 27 Jul 2020
    2.4
    Low

    CVE-2020-9251

    Last Modified: 21 Nov 2024

    HUAWEI Mate 20 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have an improper authorization vulnerability. The software does not properly restrict certain operation in certain scenario, the attacker should do certain configuration before the user turns on student mode function. Successful exploit could allow the attacker to bypass the limit of student mode function. Affected product versions include: HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8).

    Published: 27 Jul 2020
    3.3
    Low

    CVE-2020-9077

    Last Modified: 21 Nov 2024

    HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing malicious software to exploit this vulnerability and obtain some information about the device. Successful exploit may cause information disclosure.

    Published: 27 Jul 2020
    5.3
    Medium

    CVE-2020-7695

    Last Modified: 21 Nov 2024

    Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to HTTP responses, or even return an arbitrary response body, whenever crafted input is used to construct HTTP headers.

    Published: 27 Jul 2020
    3.7
    Low

    CVE-2020-7694

    Last Modified: 21 Nov 2024

    This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever any HTTP request is received, the default behaviour of uvicorn is to log its details to either the console or a log file. When attackers request crafted URLs with percent-encoded escape sequences, the logging component will log the URL after it's been processed with urllib.parse.unquote, therefore converting any percent-encoded characters into their single-character equivalent, which can have special meaning in terminal emulators. By requesting URLs with crafted paths, attackers can: * Pollute uvicorn's access logs, therefore jeopardising the integrity of such files. * Use ANSI sequence codes to attempt to interact with the terminal emulator that's displaying the logs (either in real time or from a file).

    Published: 27 Jul 2020
    8.8
    High

    CVE-2020-5611

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 27 Jul 2020
    7.4
    High

    CVE-2020-15953

    Last Modified: 21 Nov 2024

    LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."

    Published: 27 Jul 2020
    6.5
    Medium

    CVE-2020-15954

    Last Modified: 21 Nov 2024

    KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

    Published: 27 Jul 2020
    6.5
    Medium

    CVE-2020-6538

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 27 Jul 2020
    6.7
    Medium

    CVE-2020-7017

    Last Modified: 21 Nov 2024

    In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.

    Published: 27 Jul 2020
    4.3
    Medium

    CVE-2020-10715

    Last Modified: 21 Nov 2024

    A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially convince a user that the inserted text is legitimate.

    Published: 27 Jul 2020
    9.1
    Critical

    CVE-2020-12403

    Last Modified: 21 Nov 2024

    A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.

    Published: 27 Jul 2020
    8.8
    High

    CVE-2020-6532

    Last Modified: 21 Nov 2024

    Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 27 Jul 2020
    8.8
    High

    CVE-2020-6540

    Last Modified: 21 Nov 2024

    Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 27 Jul 2020
    9.8
    Critical

    CVE-2020-15900

    Last Modified: 21 Nov 2024

    A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.

    Published: 27 Jul 2020
    3.8
    Low

    CVE-2020-16092

    Last Modified: 21 Nov 2024

    In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.

    Published: 27 Jul 2020
    6.7
    Medium

    CVE-2020-24612

    Last Modified: 21 Nov 2024

    An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default when configured by the authselect tool), and that file cannot be read, the second factor is disabled. An attacker with only the knowledge of the password can then log in, bypassing 2FA.

    Published: 27 Jul 2020
    8.8
    High

    CVE-2020-6537

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Published: 27 Jul 2020
    8.8
    High

    CVE-2020-6539

    Last Modified: 21 Nov 2024

    Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 27 Jul 2020
    8.8
    High

    CVE-2020-6541

    Last Modified: 21 Nov 2024

    Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 27 Jul 2020
    4.8
    Medium

    CVE-2020-7016

    Last Modified: 21 Nov 2024

    Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.

    Published: 27 Jul 2020
    7.5
    High

    CVE-2020-7687

    Last Modified: 21 Nov 2024

    This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.

    Published: 25 Jul 2020
    7.5
    High

    CVE-2020-7686

    Last Modified: 21 Nov 2024

    This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.

    Published: 25 Jul 2020
    7.5
    High

    CVE-2020-7681

    Last Modified: 21 Nov 2024

    This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.

    Published: 25 Jul 2020
    7.5
    High

    CVE-2020-7682

    Last Modified: 21 Nov 2024

    This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.

    Published: 25 Jul 2020
    7.5
    High

    CVE-2020-7683

    Last Modified: 21 Nov 2024

    This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.

    Published: 25 Jul 2020