CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-8541

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.3 allows XXE attacks.

    Published: 16 Jun 2020
    5.4
    Medium

    CVE-2020-8542

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.3 allows XSS.

    Published: 16 Jun 2020
    7.5
    High

    CVE-2020-8543

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.3 has Improper Input Validation.

    Published: 16 Jun 2020
    6.5
    Medium

    CVE-2020-4320

    Last Modified: 21 Nov 2024

    IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.

    Published: 16 Jun 2020
    7.5
    High

    CVE-2020-4310

    Last Modified: 21 Nov 2024

    IBM MQ and MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 C are vulnerable to a denial of service attack due to an error within the Data Conversion logic. IBM X-Force ID: 177081.

    Published: 16 Jun 2020
    7.8
    High

    CVE-2019-18614

    Last Modified: 21 Nov 2024

    On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow. This is because the maximum BLOC buffer size for sending and receiving data is set to 384 bytes, but everything else is still configured to the usual size of 1092 (which was used for everything in the previous CYW20719 and later CYW20819 evaluation board). To trigger the overflow, an attacker can either send packets over the air or as unprivileged local user. Over the air, the minimal PoC is sending "l2ping -s 600" to the target address prior to any pairing. Locally, the buffer overflow is immediately triggered by opening an ACL or SCO connection to a headset. This occurs because, in WICED Studio 6.2 and 6.4, BT_ACL_HOST_TO_DEVICE_DEFAULT_SIZE and BT_ACL_DEVICE_TO_HOST_DEFAULT_SIZE are set to 384.

    Published: 16 Jun 2020
    9.8
    Critical

    CVE-2020-0223

    Last Modified: 21 Nov 2024

    This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450

    Published: 16 Jun 2020
    9.8
    Critical

    CVE-2020-0235

    Last Modified: 21 Nov 2024

    In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "struct crus_sp_ioctl_header".Product: AndroidVersions: Android kernelAndroid ID: A-135129430

    Published: 16 Jun 2020
    9.8
    Critical

    CVE-2020-0232

    Last Modified: 21 Nov 2024

    Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread could retrieve created transfer object from the session object and delete it using abc_pcie_dma_user_xfer_clean. If this happens, abc_pcie_start_dma_xfer and abc_pcie_wait_dma_xfer in the original thread will trigger UAF when working with the transfer object.Product: AndroidVersions: Android kernelAndroid ID: A-151453714

    Published: 16 Jun 2020
    7.8
    High

    CVE-2020-0234

    Last Modified: 21 Nov 2024

    In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-148189280

    Published: 16 Jun 2020
    5.3
    Medium

    CVE-2020-12494

    Last Modified: 21 Nov 2024

    Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames. By this method, memory content is disclosed, however, an attacker can hardly control which memory content is affected. For example, the disclosure can be provoked with small sized ICMP echo requests sent to the device.

    Published: 16 Jun 2020
    9.8
    Critical

    CVE-2020-9296

    Last Modified: 21 Nov 2024

    Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error message template being passed to ConstraintValidatorContext.buildConstraintViolationWithTemplate() argument, they will be able to run arbitrary Java code.

    Published: 16 Jun 2020
    4.3
    Medium

    CVE-2020-11841

    Last Modified: 21 Nov 2024

    Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure.

    Published: 16 Jun 2020
    5.4
    Medium

    CVE-2020-11838

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.

    Published: 16 Jun 2020
    4.3
    Medium

    CVE-2020-11840

    Last Modified: 21 Nov 2024

    Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure.

    Published: 16 Jun 2020
    6.1
    Medium

    CVE-2020-9522

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure.

    Published: 16 Jun 2020
    7.8
    High

    CVE-2020-13431

    Last Modified: 21 Nov 2024

    I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.

    Published: 16 Jun 2020
    5.9
    Medium

    CVE-2020-14954

    Last Modified: 21 Nov 2024

    Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."

    Published: 16 Jun 2020
    3.7
    Low

    CVE-2020-4053

    Last Modified: 21 Nov 2024

    In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plugins from a tar archive over HTTP. It is possible for a malicious plugin author to inject a relative path into a plugin archive, and copy a file outside of the intended directory. This has been fixed in 3.2.4.

    Published: 16 Jun 2020
    6.7
    Medium

    CVE-2020-5358

    Last Modified: 21 Nov 2024

    Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the help of a symbolic link.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-14163

    Last Modified: 21 Nov 2024

    An issue was discovered in ecma/operations/ecma-container-object.c in JerryScript 2.2.0. Operations with key/value pairs did not consider the case where garbage collection is triggered after the key operation but before the value operation, as demonstrated by improper read access to memory in ecma_gc_set_object_visited in ecma/base/ecma-gc.c.

    Published: 15 Jun 2020
    7.8
    High

    CVE-2020-5755

    Last Modified: 21 Nov 2024

    Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.

    Published: 15 Jun 2020
    9.1
    Critical

    CVE-2020-5754

    Last Modified: 21 Nov 2024

    Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-5742

    Last Modified: 21 Nov 2024

    Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-12005

    Last Modified: 21 Nov 2024

    FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000 Launcher: Version 31 and later Stud, 5000 Logix Designer software: Version 32 and prior is vulnerable. A vulnerability exists in the communication function that enables users to upload EDS files by FactoryTalk Linx. This may allow an attacker to upload a file with bad compression, consuming all the available CPU resources, leading to a denial-of-service condition.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-12003

    Last Modified: 21 Nov 2024

    FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000 Launcher: Version 31 and later Stud, 5000 Logix Designer software: Version 32 and prior is vulnerable. An exposed API call allows users to provide files to be processed without sanitation. This may allow an attacker to use specially crafted requests to traverse the file system and expose sensitive data on the local hard drive.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-12001

    Last Modified: 21 Nov 2024

    FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000 Launcher: Version 31 and later Stud, 5000 Logix Designer software: Version 32 and prior is vulnerable. The parsing mechanism that processes certain file types does not provide input sanitation. This may allow an attacker to use specially crafted files to traverse the file system and modify or expose sensitive data or execute arbitrary code.

    Published: 15 Jun 2020
    8.1
    High

    CVE-2020-11999

    Last Modified: 21 Nov 2024

    FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000 Launcher: Version 31 and later Stud, 5000 Logix Designer software: Version 32 and prior is vulnerable. An exposed API call allows users to provide files to be processed without sanitation. This may allow an attacker to specify a filename to execute unauthorized code and modify files or data.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-12019

    Last Modified: 21 Nov 2024

    WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-11969

    Last Modified: 21 Nov 2024

    If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache TomEE 7.1.0 - 7.1.2, Apache TomEE 7.0.0-M1 - 7.0.7, Apache TomEE 1.0.0 - 1.7.5.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-14159

    Last Modified: 21 Nov 2024

    By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before 2019.12.337, 2020 before 2020.1.53, 2020.2 before 2020.2.85, 2020.3 before 2020.3.114, 2020.4 before 2020.4.143, and 2020.5 before 2020.5.178.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-13650

    Last Modified: 21 Nov 2024

    An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an external server, a forged request discloses application credentials. For a request to an internal component, the request is blind, but through the error message it's possible to determine whether the request targeted a open service.

    Published: 15 Jun 2020
    7.8
    High

    CVE-2020-13651

    Last Modified: 21 Nov 2024

    An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by a client to obtain the right Java application. By providing an attacker-controlled URL, the client will obtain a rogue JNLP file specifying the installation of malicious JAR archives and executed with full privileges on the client computer.

    Published: 15 Jun 2020
    6.1
    Medium

    CVE-2020-13652

    Last Modified: 21 Nov 2024

    An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200528, 2019R2 before p20200430, and 2020R1 before p20200507. A cross-site scripting (XSS) vulnerability exists in the login menu.

    Published: 15 Jun 2020
    8.8
    High

    CVE-2020-14156

    Last Modified: 21 Nov 2024

    user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-14148

    Last Modified: 21 Nov 2024

    The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.

    Published: 15 Jun 2020
    7.5
    High

    CVE-2020-14149

    Last Modified: 21 Nov 2024

    In uftpd before 2.12, handle_CWD in ftpcmd.c mishandled the path provided by the user, causing a NULL pointer dereference and denial of service, as demonstrated by a CWD /.. command.

    Published: 15 Jun 2020
    9.1
    Critical

    CVE-2018-21245

    Last Modified: 21 Nov 2024

    Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2018-21246

    Last Modified: 21 Nov 2024

    Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-14033

    Last Modified: 21 Nov 2024

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Overflow via a crafted RTSP server.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-14034

    Last Modified: 21 Nov 2024

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.

    Published: 15 Jun 2020
    7.8
    High

    CVE-2020-13150

    Last Modified: 21 Nov 2024

    D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filtering rules become active.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-14054

    Last Modified: 21 Nov 2024

    SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows remote attackers to bypass admin authentication via a SQL injection attack that uses the User Name or Password field on the login page.

    Published: 15 Jun 2020
    7.8
    High

    CVE-2020-3961

    Last Modified: 21 Nov 2024

    VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe loading of libraries. A local user on the system where the software is installed may exploit this issue to run commands as any user.

    Published: 15 Jun 2020
    6.8
    Medium

    CVE-2020-9076

    Last Modified: 21 Nov 2024

    HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not being properly verified, an attacker can exploit this vulnerability through man-in-the-middle attack to induce user to access malicious URL.

    Published: 15 Jun 2020
    6.5
    Medium

    CVE-2020-1825

    Last Modified: 21 Nov 2024

    FusionAccess with versions earlier than 6.5.1.SPC002 have a Denial of Service (DoS) vulnerability. Due to insufficient verification on specific input, attackers can exploit this vulnerability by sending constructed messages to the affected device through another device on the same network. Successful exploit could cause affected devices to be abnormal.

    Published: 15 Jun 2020
    6.5
    Medium

    CVE-2020-9075

    Last Modified: 21 Nov 2024

    Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,V500R005C10;V600R006C00 have a vulnerability of insufficient input verification. An attacker with limited privilege can exploit this vulnerability to access a specific directory. Successful exploitation of this vulnerability may lead to information leakage.

    Published: 15 Jun 2020
    6.1
    Medium

    CVE-2020-9426

    Last Modified: 21 Nov 2024

    OX Guard 2.10.3 and earlier allows XSS.

    Published: 15 Jun 2020
    5
    Medium

    CVE-2020-9427

    Last Modified: 21 Nov 2024

    OX Guard 2.10.3 and earlier allows SSRF.

    Published: 15 Jun 2020
    9.8
    Critical

    CVE-2020-14011

    Last Modified: 21 Nov 2024

    Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled Deployments features.

    Published: 15 Jun 2020