CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2020-9395

    Last Modified: 21 Nov 2024

    An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata buffer.

    Published: 6 Jul 2020
    6.3
    Medium

    CVE-2020-1839

    Last Modified: 21 Nov 2024

    HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a race condition vulnerability. There is a timing window exists in which certain pointer members can be modified by another process that is operating concurrently, an attacker should trick the user into running a crafted application with high privilege, successful exploit could cause code execution.

    Published: 6 Jul 2020
    5.3
    Medium

    CVE-2020-1836

    Last Modified: 21 Nov 2024

    HUAWEI P30 with versions earlier than 10.1.0.160(C00E160R2P11) and HUAWEI P30 Pro with versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain function's default configuration in the system seems insecure, an attacker should craft a WI-FI hotspot to launch the attack. Successful exploit could cause information disclosure.

    Published: 6 Jul 2020
    5.5
    Medium

    CVE-2020-9226

    Last Modified: 21 Nov 2024

    HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability. The system does not improper check signature of specific software package, an attacker may exploit this vulnerability to load a crafted software package to the device.

    Published: 6 Jul 2020
    7.8
    High

    CVE-2020-9261

    Last Modified: 21 Nov 2024

    HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a type confusion vulnerability. The system does not properly check and transform the type of certain variable, the attacker tricks the user into installing then running a crafted application, successful exploit could cause code execution.

    Published: 6 Jul 2020
    5.5
    Medium

    CVE-2020-1838

    Last Modified: 21 Nov 2024

    HUAWEI Mate 30 Pro with versions earlier than 10.1.0.150(C00E136R5P3) have is an improper authentication vulnerability. The device does not sufficiently validate certain credential of user's face, an attacker could craft the credential of the user, successful exploit could allow the attacker to pass the authentication with the crafted credential.

    Published: 6 Jul 2020
    7.8
    High

    CVE-2020-9262

    Last Modified: 21 Nov 2024

    HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a use after free vulnerability. There is a condition exists that the system would reference memory after it has been freed, the attacker should trick the user into running a crafted application with high privilege, successful exploit could cause code execution.

    Published: 6 Jul 2020
    8.8
    High

    CVE-2020-6013

    Last Modified: 21 Nov 2024

    ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems.

    Published: 6 Jul 2020
    8.6
    High

    CVE-2020-5372

    Last Modified: 21 Nov 2024

    Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which are not used during run time environment.

    Published: 6 Jul 2020
    8
    High

    CVE-2020-5371

    Last Modified: 21 Nov 2024

    Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability. An attacker, with network or local file access, could take advantage of insufficiently applied file permissions or gain unauthorized access to files.

    Published: 6 Jul 2020
    9.8
    Critical

    CVE-2020-5368

    Last Modified: 21 Nov 2024

    Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

    Published: 6 Jul 2020
    7.7
    High

    CVE-2020-5356

    Last Modified: 21 Nov 2024

    Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected PowerProtect virtual machines.

    Published: 6 Jul 2020
    8.8
    High

    CVE-2020-5352

    Last Modified: 21 Nov 2024

    Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit this vulnerability to execute arbitrary commands on the affected system.

    Published: 6 Jul 2020
    7.8
    High

    CVE-2019-8249

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 6 Jul 2020
    5.5
    Medium

    CVE-2019-8252

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploitation could lead to information disclosure.

    Published: 6 Jul 2020
    5.5
    Medium

    CVE-2019-8251

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploitation could lead to information disclosure.

    Published: 6 Jul 2020
    7.8
    High

    CVE-2019-8066

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 6 Jul 2020
    7.8
    High

    CVE-2019-8250

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 6 Jul 2020
    5.3
    Medium

    CVE-2020-1837

    Last Modified: 21 Nov 2024

    ChangXiang 8 Plus with versions earlier than 9.1.0.136(C00E121R1P6T8) have a denial of service vulnerability. The device does not properly handle certain message from base station, the attacker could craft a fake base station to launch the attack. Successful exploit could cause a denial of signal service condition.

    Published: 6 Jul 2020
    7.8
    High

    CVE-2020-9100

    Last Modified: 21 Nov 2024

    Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this DLL file of the attacker's choosing.

    Published: 6 Jul 2020
    5.5
    Medium

    CVE-2020-15570

    Last Modified: 21 Nov 2024

    The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows an attacker to cause a denial of service via a malformed crash file.

    Published: 6 Jul 2020
    5.5
    Medium

    CVE-2020-15569

    Last Modified: 21 Nov 2024

    PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destructor.

    Published: 6 Jul 2020
    6.1
    Medium

    CVE-2020-7690

    Last Modified: 21 Nov 2024

    All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.

    Published: 6 Jul 2020
    6.3
    Medium

    CVE-2020-7691

    Last Modified: 21 Nov 2024

    In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.

    Published: 6 Jul 2020
    6.1
    Medium

    CVE-2020-15562

    Last Modified: 21 Nov 2024

    An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.

    Published: 6 Jul 2020
    4.3
    Medium

    CVE-2020-14313

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.

    Published: 6 Jul 2020
    9.8
    Critical

    CVE-2020-15889

    Last Modified: 21 Nov 2024

    Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.

    Published: 6 Jul 2020
    7.8
    High

    CVE-2020-24342

    Last Modified: 21 Nov 2024

    Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.

    Published: 6 Jul 2020
    8.8
    High

    CVE-2020-15888

    Last Modified: 21 Nov 2024

    Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.

    Published: 6 Jul 2020
    5.5
    Medium

    CVE-2020-35538

    Last Modified: 21 Nov 2024

    A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.

    Published: 6 Jul 2020
    9.8
    Critical

    CVE-2020-15541

    Last Modified: 21 Nov 2024

    SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

    Published: 5 Jul 2020
    9.8
    Critical

    CVE-2020-15543

    Last Modified: 21 Nov 2024

    SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.

    Published: 5 Jul 2020
    9.8
    Critical

    CVE-2020-15542

    Last Modified: 21 Nov 2024

    SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.

    Published: 5 Jul 2020
    6.1
    Medium

    CVE-2020-15535

    Last Modified: 21 Nov 2024

    An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields.

    Published: 5 Jul 2020
    6.1
    Medium

    CVE-2020-15536

    Last Modified: 21 Nov 2024

    An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.

    Published: 5 Jul 2020
    6.1
    Medium

    CVE-2020-15537

    Last Modified: 21 Nov 2024

    An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/ URI, or the Products Search box.

    Published: 5 Jul 2020
    6.1
    Medium

    CVE-2020-15538

    Last Modified: 21 Nov 2024

    XSS can occur in We-com Municipality portal CMS 2.1.x via the cerca/ search bar.

    Published: 5 Jul 2020
    9.8
    Critical

    CVE-2020-15539

    Last Modified: 21 Nov 2024

    SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.

    Published: 5 Jul 2020
    9.8
    Critical

    CVE-2020-15540

    Last Modified: 21 Nov 2024

    We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.

    Published: 5 Jul 2020
    7.8
    High

    CVE-2020-15528

    Last Modified: 21 Nov 2024

    An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of weak file permissions and missing file integrity checks.

    Published: 5 Jul 2020
    7.8
    High

    CVE-2020-15529

    Last Modified: 21 Nov 2024

    An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists because of weak file permissions and can be exploited by using opportunistic locks.

    Published: 5 Jul 2020
    7.8
    High

    CVE-2020-15530

    Last Modified: 21 Nov 2024

    An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam and/or %COMMONPROGRAMFILES(X86)%\Steam have weak permissions during a critical time window. An attacker can make this time window arbitrarily long by using opportunistic locks.

    Published: 5 Jul 2020
    7.5
    High

    CVE-2020-15466

    Last Modified: 21 Nov 2024

    In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.

    Published: 5 Jul 2020
    7.8
    High

    CVE-2020-15523

    Last Modified: 21 Nov 2024

    In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue CANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows.

    Published: 4 Jul 2020
    5.9
    Medium

    CVE-2020-14928

    Last Modified: 21 Nov 2024

    evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."

    Published: 4 Jul 2020
    5.6
    Medium

    CVE-2020-15366

    Last Modified: 21 Nov 2024

    An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)

    Published: 4 Jul 2020
    8.6
    High

    CVE-2020-7284

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to gain unauthorised access to the root account via execution of carefully crafted commands from the restricted command line interface (CLI).

    Published: 3 Jul 2020
    9.8
    Critical

    CVE-2020-10282

    Last Modified: 21 Nov 2024

    The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity spoofing, unauthorized access, PITM attacks and more. According to literature, version 2.0 optionally allows for package signing which mitigates this flaw. Another source mentions that MAVLink 2.0 only provides a simple authentication system based on HMAC. This implies that the flying system overall should add the same symmetric key into all devices of network. If not the case, this may cause a security issue, that if one of the devices and its symmetric key are compromised, the whole authentication system is not reliable.

    Published: 3 Jul 2020
    7.5
    High

    CVE-2020-10281

    Last Modified: 21 Nov 2024

    This vulnerability applies to the Micro Air Vehicle Link (MAVLink) protocol and allows a remote attacker to gain access to sensitive information provided it has access to the communication medium. MAVLink is a header-based protocol that does not perform encryption to improve transfer (and reception speed) and efficiency by design. The increasing popularity of the protocol (used accross different autopilots) has led to its use in wired and wireless mediums through insecure communication channels exposing sensitive information to a remote attacker with ability to intercept network traffic.

    Published: 3 Jul 2020
    7.5
    High

    CVE-2020-7283

    Last Modified: 21 Nov 2024

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This is achieved through running a malicious script or program on the target machine.

    Published: 3 Jul 2020