CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2020-3289

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending crafted requests that contain overly large values to an affected device, causing a stack overflow. A successful exploit could allow the attacker to cause the device to crash or allow the attacker to execute arbitrary code with root privileges on the underlying operating system.

    Published: 18 Jun 2020
    7.2
    High

    CVE-2020-3288

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending crafted requests that contain overly large values to an affected device, causing a stack overflow. A successful exploit could allow the attacker to cause the device to crash or allow the attacker to execute arbitrary code with root privileges on the underlying operating system.

    Published: 18 Jun 2020
    7.2
    High

    CVE-2020-3287

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending crafted requests that contain overly large values to an affected device, causing a stack overflow. A successful exploit could allow the attacker to cause the device to crash or allow the attacker to execute arbitrary code with root privileges on the underlying operating system.

    Published: 18 Jun 2020
    7.2
    High

    CVE-2020-3286

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending crafted requests that contain overly large values to an affected device, causing a stack overflow. A successful exploit could allow the attacker to cause the device to crash or allow the attacker to execute arbitrary code with root privileges on the underlying operating system.

    Published: 18 Jun 2020
    7.2
    High

    CVE-2020-3279

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary commands on an affected device. The vulnerabilities exist because the web-based management interface does not properly validate user-supplied input to scripts. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending malicious requests to an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.

    Published: 18 Jun 2020
    7.2
    High

    CVE-2020-3278

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary commands on an affected device. The vulnerabilities exist because the web-based management interface does not properly validate user-supplied input to scripts. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending malicious requests to an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.

    Published: 18 Jun 2020
    7.2
    High

    CVE-2020-3277

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary commands on an affected device. The vulnerabilities exist because the web-based management interface does not properly validate user-supplied input to scripts. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending malicious requests to an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.

    Published: 18 Jun 2020
    4.2
    Medium

    CVE-2020-14416

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.

    Published: 18 Jun 2020
    5.9
    Medium

    CVE-2020-14422

    Last Modified: 21 Nov 2024

    Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.

    Published: 18 Jun 2020
    8.1
    High

    CVE-2020-14157

    Last Modified: 21 Nov 2024

    The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity chip keys (RFID tokens). This makes it easier for an attacker to disarm the wireless alarm system.

    Published: 17 Jun 2020
    6.1
    Medium

    CVE-2020-14408

    Last Modified: 21 Nov 2024

    An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.

    Published: 17 Jun 2020
    5.3
    Medium

    CVE-2020-4532

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182716.

    Published: 17 Jun 2020
    8.1
    High

    CVE-2020-6869

    Last Modified: 21 Nov 2024

    All versions up to 10.06 of ZTEMarket APK are impacted by an information leak vulnerability. Due to Activity Component exposure users can exploit this vulnerability to get the private cookie and execute silent installation.

    Published: 17 Jun 2020
    7.8
    High

    CVE-2020-9332

    Last Modified: 21 Nov 2024

    ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code related to a USB HID device.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2020-13637

    Last Modified: 21 Nov 2024

    An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end encryption in cleartext, enabling an attacker (by copying or having access to the local storage database file) to login to the system from any other computer, and get unlimited access to all data in the users's context.

    Published: 17 Jun 2020
    3.8
    Low

    CVE-2020-6752

    Last Modified: 21 Nov 2024

    In OMERO before 5.6.1, group owners can access members' data in other groups.

    Published: 17 Jun 2020
    5.3
    Medium

    CVE-2019-16245

    Last Modified: 21 Nov 2024

    OMERO before 5.6.1 makes the details of each user available to all users.

    Published: 17 Jun 2020
    5.7
    Medium

    CVE-2020-7932

    Last Modified: 21 Nov 2024

    OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2019-9943

    Last Modified: 21 Nov 2024

    In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2019-9944

    Last Modified: 21 Nov 2024

    In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions. This occurs because the Bio-Formats feature allows an image file to have embedded pathnames.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2020-7668

    Last Modified: 21 Nov 2024

    In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2020-7664

    Last Modified: 21 Nov 2024

    In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

    Published: 17 Jun 2020
    —
    Unknown

    CVE-2020-10747

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 17 Jun 2020
    7.2
    High

    CVE-2020-14295

    Last Modified: 21 Nov 2024

    A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

    Published: 17 Jun 2020
    7.2
    High

    CVE-2020-12827

    Last Modified: 21 Nov 2024

    MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.

    Published: 17 Jun 2020
    8.8
    High

    CVE-2020-13224

    Last Modified: 21 Nov 2024

    TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a Buffer Overflow

    Published: 17 Jun 2020
    4.3
    Medium

    CVE-2020-11914

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.

    Published: 17 Jun 2020
    5.3
    Medium

    CVE-2020-11913

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

    Published: 17 Jun 2020
    5.3
    Medium

    CVE-2020-11912

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.

    Published: 17 Jun 2020
    5.3
    Medium

    CVE-2020-11911

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.

    Published: 17 Jun 2020
    5.3
    Medium

    CVE-2020-11910

    Last Modified: 30 Sept 2025

    The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.

    Published: 17 Jun 2020
    5.3
    Medium

    CVE-2020-11909

    Last Modified: 30 Sept 2025

    The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.

    Published: 17 Jun 2020
    4.3
    Medium

    CVE-2020-11908

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.

    Published: 17 Jun 2020
    6.3
    Medium

    CVE-2020-11907

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP.

    Published: 17 Jun 2020
    6.3
    Medium

    CVE-2020-11906

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.

    Published: 17 Jun 2020
    6.5
    Medium

    CVE-2020-11905

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.

    Published: 17 Jun 2020
    7.3
    High

    CVE-2020-11904

    Last Modified: 30 Sept 2025

    The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.

    Published: 17 Jun 2020
    6.5
    Medium

    CVE-2020-11903

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.

    Published: 17 Jun 2020
    7.3
    High

    CVE-2020-11902

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.

    Published: 17 Jun 2020
    9
    Critical

    CVE-2020-11901

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.

    Published: 17 Jun 2020
    8.2
    High

    CVE-2020-11900

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.

    Published: 17 Jun 2020
    5.4
    Medium

    CVE-2020-11899

    Last Modified: 7 Nov 2025

    The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.

    Published: 17 Jun 2020
    9.1
    Critical

    CVE-2020-11898

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.

    Published: 17 Jun 2020
    10
    Critical

    CVE-2020-11897

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.

    Published: 17 Jun 2020
    10
    Critical

    CVE-2020-11896

    Last Modified: 21 Nov 2024

    The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.

    Published: 17 Jun 2020
    5.5
    Medium

    CVE-2020-10781

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kernel memory and is not accounted for a user that triggers the creation of that ZRAM device. With this vulnerability, continually reading the device may consume a large amount of system memory and cause the Out-of-Memory (OOM) killer to activate and terminate random userspace processes, possibly making the system inoperable.

    Published: 17 Jun 2020
    4.9
    Medium

    CVE-2020-8619

    Last Modified: 1 Sept 2026

    In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2019-20839

    Last Modified: 21 Nov 2024

    libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2020-14040

    Last Modified: 21 Nov 2024

    The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2020-14396

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference.

    Published: 17 Jun 2020