CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-14397

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2020-14399

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.

    Published: 17 Jun 2020
    5.4
    Medium

    CVE-2020-14403

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2019-20840

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.

    Published: 17 Jun 2020
    6.5
    Medium

    CVE-2020-10782

    Last Modified: 21 Nov 2024

    An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable and exposed from the rsyslog configuration file, which has set the wrong world-readable permissions. The highest threat from this vulnerability is to confidentiality. This is fixed in Ansible version 3.7.1.

    Published: 17 Jun 2020
    —
    Unknown

    CVE-2020-14395

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2020-14400

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary

    Published: 17 Jun 2020
    6.5
    Medium

    CVE-2020-14401

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.

    Published: 17 Jun 2020
    5.4
    Medium

    CVE-2020-14404

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.

    Published: 17 Jun 2020
    6.5
    Medium

    CVE-2020-14405

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.

    Published: 17 Jun 2020
    2.3
    Low

    CVE-2020-15469

    Last Modified: 21 Nov 2024

    In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

    Published: 17 Jun 2020
    6.5
    Medium

    CVE-2020-8185

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.

    Published: 17 Jun 2020
    4.9
    Medium

    CVE-2020-8618

    Last Modified: 21 Nov 2024

    An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2020-14398

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.

    Published: 17 Jun 2020
    5.4
    Medium

    CVE-2020-14402

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.

    Published: 17 Jun 2020
    7.5
    High

    CVE-2018-21247

    Last Modified: 21 Nov 2024

    An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

    Published: 17 Jun 2020
    6.5
    Medium

    CVE-2020-14214

    Last Modified: 21 Nov 2024

    Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can register a new account that will have access to all tickets of an arbitrary Organization.

    Published: 16 Jun 2020
    5.4
    Medium

    CVE-2020-14213

    Last Modified: 21 Nov 2024

    In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).

    Published: 16 Jun 2020
    7.3
    High

    CVE-2020-4054

    Last Modified: 21 Nov 2024

    In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulnerability. When HTML is sanitized using Sanitize's "relaxed" config, or a custom config that allows certain elements, some content in a math or svg element may not be sanitized correctly even if math and svg are not in the allowlist. You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements: iframe, math, noembed, noframes, noscript, plaintext, script, style, svg, xmp. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. This has been fixed in 5.2.1.

    Published: 16 Jun 2020
    8.8
    High

    CVE-2020-14212

    Last Modified: 21 Nov 2024

    FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.

    Published: 16 Jun 2020
    6.3
    Medium

    CVE-2020-4052

    Last Modified: 21 Nov 2024

    In Wiki.js before 2.4.107, there is a stored cross-site scripting through template injection. This vulnerability exists due to an insecure validation mechanism intended to insert v-pre tags into rendered HTML elements which contain curly-braces. By creating a crafted wiki page, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the page is viewed by other users. This has been patched in 2.4.107.

    Published: 16 Jun 2020
    6.1
    Medium

    CVE-2020-14210

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting (XSS) vulnerability in MONITORAPP WAF in which script can be executed when responding to Request URL information. It provides a function to response to Request URL information when blocking.

    Published: 16 Jun 2020
    5.3
    Medium

    CVE-2019-17655

    Last Modified: 21 Nov 2024

    A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.

    Published: 16 Jun 2020
    7.5
    High

    CVE-2020-9289

    Last Modified: 21 Nov 2024

    Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.

    Published: 16 Jun 2020
    7.5
    High

    CVE-2020-7513

    Last Modified: 21 Nov 2024

    A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to intercept traffic and read configuration data.

    Published: 16 Jun 2020
    9.8
    Critical

    CVE-2020-7512

    Last Modified: 21 Nov 2024

    A CWE-1103: Use of Platform-Dependent Third Party Components with vulnerabilities vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to exploit the component.

    Published: 16 Jun 2020
    7.5
    High

    CVE-2020-7511

    Last Modified: 21 Nov 2024

    A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to acquire a password by brute force.

    Published: 16 Jun 2020
    7.5
    High

    CVE-2020-7510

    Last Modified: 21 Nov 2024

    A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtain private keys.

    Published: 16 Jun 2020
    7.2
    High

    CVE-2020-7509

    Last Modified: 21 Nov 2024

    A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to elevate their privileges and delete files.

    Published: 16 Jun 2020
    9.8
    Critical

    CVE-2020-7508

    Last Modified: 21 Nov 2024

    A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.

    Published: 16 Jun 2020
    7.5
    High

    CVE-2020-7507

    Last Modified: 21 Nov 2024

    A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to login multiple times resulting in a denial of service.

    Published: 16 Jun 2020
    7.5
    High

    CVE-2020-7506

    Last Modified: 21 Nov 2024

    A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an attacker to pack or unpack the archive with the firmware for the controller and modules using the usual tar archiver resulting in an information exposure.

    Published: 16 Jun 2020
    7.2
    High

    CVE-2020-7505

    Last Modified: 21 Nov 2024

    A CWE-494 Download of Code Without Integrity Check vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to inject data with dangerous content into the firmware and execute arbitrary code on the system.

    Published: 16 Jun 2020
    5.3
    Medium

    CVE-2020-7504

    Last Modified: 21 Nov 2024

    A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable the webserver service on the device when specially crafted network packets are sent.

    Published: 16 Jun 2020
    8.8
    High

    CVE-2020-7503

    Last Modified: 21 Nov 2024

    A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-token data is intercepted.

    Published: 16 Jun 2020
    7
    High

    CVE-2020-13162

    Last Modified: 5 May 2025

    A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.

    Published: 16 Jun 2020
    7.5
    High

    CVE-2020-7502

    Last Modified: 21 Nov 2024

    A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), which may cause a Denial of Service when specific TCP/IP crafted packets are sent to the Modicon M218 Logic Controller.

    Published: 16 Jun 2020
    8.8
    High

    CVE-2020-7501

    Last Modified: 21 Nov 2024

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer.

    Published: 16 Jun 2020
    9.8
    Critical

    CVE-2020-7500

    Last Modified: 21 Nov 2024

    A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.

    Published: 16 Jun 2020
    6.5
    Medium

    CVE-2020-7499

    Last Modified: 21 Nov 2024

    A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low privileged user makes unauthorized changes.

    Published: 16 Jun 2020
    9.8
    Critical

    CVE-2020-7498

    Last Modified: 21 Nov 2024

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fixed credentials is considered a vulnerability, which could cause unauthorized access to the file transfer service provided by the Modicon PLCs. This could result in various unintended results.

    Published: 16 Jun 2020
    9.8
    Critical

    CVE-2020-7497

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts.

    Published: 16 Jun 2020
    7.8
    High

    CVE-2020-7496

    Last Modified: 21 Nov 2024

    A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file.

    Published: 16 Jun 2020
    5.5
    Medium

    CVE-2020-7495

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when opening the project file.

    Published: 16 Jun 2020
    7.8
    High

    CVE-2020-7494

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.

    Published: 16 Jun 2020
    7.8
    High

    CVE-2020-7493

    Last Modified: 21 Nov 2024

    A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.

    Published: 16 Jun 2020
    6.5
    Medium

    CVE-2020-7492

    Last Modified: 21 Nov 2024

    A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded.

    Published: 16 Jun 2020
    6.1
    Medium

    CVE-2020-10268

    Last Modified: 21 Nov 2024

    Critical services for operation can be terminated from windows task manager, bringing the manipulator to a halt. After this a Re-Calibration of the brakes needs to be performed. Be noted that this only can be accomplished either by a Kuka technician or by Kuka issued calibration hardware that interfaces with the manipulator furthering the delay and increasing operational costs.

    Published: 16 Jun 2020
    6.5
    Medium

    CVE-2020-14199

    Last Modified: 21 Nov 2024

    BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this affects all hardware wallets. It was fixed in 1.9.1 for the Trezor One and 2.3.1 for the Trezor Model T.

    Published: 16 Jun 2020
    6.5
    Medium

    CVE-2020-8544

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.3 allows SSRF.

    Published: 16 Jun 2020