CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2020-13853

    Last Modified: 21 Nov 2024

    Artica Pandora FMS 7.44 has persistent XSS in the Messages feature.

    Published: 11 Jun 2020
    9.8
    Critical

    CVE-2020-13854

    Last Modified: 21 Nov 2024

    Artica Pandora FMS 7.44 allows privilege escalation.

    Published: 11 Jun 2020
    7.2
    High

    CVE-2020-13855

    Last Modified: 21 Nov 2024

    Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.

    Published: 11 Jun 2020
    7.5
    High

    CVE-2020-13850

    Last Modified: 21 Nov 2024

    Artica Pandora FMS 7.44 has inadequate access controls on a web folder.

    Published: 11 Jun 2020
    5.3
    Medium

    CVE-2020-13998

    Last Modified: 21 Nov 2024

    Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jun 2020
    7
    High

    CVE-2020-12850

    Last Modified: 21 Nov 2024

    The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0.3) have a looser policy restriction allowing the “pydio” user to execute any privileged command using sudo. In version 2.0.4 of the appliance, the user pydio is responsible for running all the services and binaries that are contained in the Pydio Cells web application package, such as mysqld, cells, among others. This user has privileges restricted to run those services and nothing more.

    Published: 11 Jun 2020
    5.9
    Medium

    CVE-2020-12714

    Last Modified: 21 Nov 2024

    An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger Virtual Appliances 1.1.1 through 3.1.1-0. A Diffie-Hellman parameter of insufficient size could allow man-in-the-middle compromise of communications between CipherMail products and external SMTP clients.

    Published: 11 Jun 2020
    7.2
    High

    CVE-2020-12713

    Last Modified: 21 Nov 2024

    An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges to the Unix root account.

    Published: 11 Jun 2020
    7.5
    High

    CVE-2020-11090

    Last Modified: 21 Nov 2024

    In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling code. The current primary can be crashed with a malformed transaction from a client, which leads to a view change. Repeated rapid view changes have the potential of bringing down the network. This is fixed in version 1.12.3.

    Published: 11 Jun 2020
    7.1
    High

    CVE-2020-14153

    Last Modified: 21 Nov 2024

    In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.

    Published: 11 Jun 2020
    0
    Low

    CVE-2020-14151

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11813. Reason: This candidate is a duplicate of CVE-2018-11813. Notes: All CVE users should reference [ID] instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Jun 2020
    7.1
    High

    CVE-2020-14152

    Last Modified: 21 Nov 2024

    In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

    Published: 11 Jun 2020
    9.8
    Critical

    CVE-2020-13901

    Last Modified: 21 Nov 2024

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.

    Published: 10 Jun 2020
    7.5
    High

    CVE-2020-13900

    Last Modified: 21 Nov 2024

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NULL pointer dereference.

    Published: 10 Jun 2020
    7.5
    High

    CVE-2020-13899

    Last Modified: 21 Nov 2024

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information from uninitialized stack memory.

    Published: 10 Jun 2020
    7.5
    High

    CVE-2020-13898

    Last Modified: 21 Nov 2024

    An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer dereference.

    Published: 10 Jun 2020
    8.6
    High

    CVE-2020-5363

    Last Modified: 21 Nov 2024

    Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This could potentially allow an unauthorized actor, with physical access and/or OS administrator privileges to the device, to gain privileged access to the platform and the hard drive.

    Published: 10 Jun 2020
    7.1
    High

    CVE-2020-5362

    Last Modified: 21 Nov 2024

    Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.

    Published: 10 Jun 2020
    7.5
    High

    CVE-2020-11622

    Last Modified: 21 Nov 2024

    A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below releases in the 4.22.x train, 4.21.3M to 4.21.9M releases in the 4.21.x train, 4.21.3FX-7368.*, 4.21.4-FCRFX.*, 4.21.4.1, 4.21.7.1, 4.22.2.0.1, 4.22.2.2.1, 4.22.3.1, and 4.23.2.1 Router code in a scenario where TCP MSS options are configured.

    Published: 10 Jun 2020
    7.5
    High

    CVE-2020-13238

    Last Modified: 21 Nov 2024

    Mitsubishi MELSEC iQ-R Series PLCs with firmware 33 allow attackers to halt the industrial process by sending an unauthenticated crafted packet over the network, because this denial of service attack consumes excessive CPU time. After halting, physical access to the PLC is required in order to restore production.

    Published: 10 Jun 2020
    7.7
    High

    CVE-2020-4043

    Last Modified: 21 Nov 2024

    phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be regarded as very high. Newer phpMussel versions don't use PHP's phar wrapper, and are therefore unaffected. This has been fixed in version 1.6.0.

    Published: 10 Jun 2020
    7.8
    High

    CVE-2020-13906

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038eb7.

    Published: 10 Jun 2020
    8.8
    High

    CVE-2020-13905

    Last Modified: 21 Nov 2024

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038ed4.

    Published: 10 Jun 2020
    6.5
    Medium

    CVE-2020-13444

    Last Modified: 21 Nov 2024

    Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.

    Published: 10 Jun 2020
    8.8
    High

    CVE-2020-13445

    Last Modified: 21 Nov 2024

    In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates.

    Published: 10 Jun 2020
    5.4
    Medium

    CVE-2020-14012

    Last Modified: 21 Nov 2024

    scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.

    Published: 10 Jun 2020
    3.8
    Low

    CVE-2020-2023

    Last Modified: 21 Nov 2024

    Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions.

    Published: 10 Jun 2020
    5.3
    Medium

    CVE-2020-2033

    Last Modified: 21 Nov 2024

    When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipulate ARP or to conduct ARP spoofing attacks. This allows the attacker to access the GlobalProtect Server as allowed by configured Security rules for the 'pre-login' user. This access may be limited compared to the network access of regular users. This issue affects: GlobalProtect app 5.0 versions earlier than GlobalProtect app 5.0.10 when the prelogon feature is enabled; GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.4 when the prelogon feature is enabled.

    Published: 10 Jun 2020
    7
    High

    CVE-2020-2032

    Last Modified: 21 Nov 2024

    A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: GlobalProtect app 5.0 versions earlier than GlobalProtect app 5.0.10 on Windows; GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.4 on Windows.

    Published: 10 Jun 2020
    7.2
    High

    CVE-2020-2029

    Last Modified: 21 Nov 2024

    An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in the PAN-OS configuration. This issue affects: All versions of PAN-OS 8.0; PAN-OS 7.1 versions earlier than PAN-OS 7.1.26; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13.

    Published: 10 Jun 2020
    7.2
    High

    CVE-2020-2028

    Last Modified: 21 Nov 2024

    An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13; PAN-OS 9.0 versions earlier than PAN-OS 9.0.7.

    Published: 10 Jun 2020
    7.2
    High

    CVE-2020-2027

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13; PAN-OS 9.0 versions earlier than PAN-OS 9.0.7.

    Published: 10 Jun 2020
    7.8
    High

    CVE-2020-2026

    Last Modified: 21 Nov 2024

    A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.

    Published: 10 Jun 2020
    6.1
    Medium

    CVE-2020-14010

    Last Modified: 21 Nov 2024

    The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parameter.

    Published: 10 Jun 2020
    5.5
    Medium

    CVE-2020-0116

    Last Modified: 21 Nov 2024

    In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-151330809

    Published: 10 Jun 2020
    9.8
    Critical

    CVE-2020-0117

    Last Modified: 21 Nov 2024

    In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-151155194

    Published: 10 Jun 2020
    5.5
    Medium

    CVE-2020-0113

    Last Modified: 21 Nov 2024

    In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-150944913

    Published: 10 Jun 2020
    7.8
    High

    CVE-2020-0118

    Last Modified: 21 Nov 2024

    In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150904694

    Published: 10 Jun 2020
    5.3
    Medium

    CVE-2020-0119

    Last Modified: 21 Nov 2024

    In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150500247

    Published: 10 Jun 2020
    7.8
    High

    CVE-2020-0115

    Last Modified: 21 Nov 2024

    In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-150038428

    Published: 10 Jun 2020
    5.5
    Medium

    CVE-2020-0121

    Last Modified: 21 Nov 2024

    In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-148180766

    Published: 10 Jun 2020
    7.8
    High

    CVE-2020-0114

    Last Modified: 21 Nov 2024

    In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147606347

    Published: 10 Jun 2020
    —
    Unknown

    CVE-2019-5731

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 10 Jun 2020
    —
    Unknown

    CVE-2019-5735

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 10 Jun 2020
    —
    Unknown

    CVE-2019-5732

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 10 Jun 2020
    9.1
    Critical

    CVE-2020-7589

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker reading and modifying the device configuration and obtain project files from affected devices. The security vulnerability could be exploited by an unauthenticated attacker with network access to port 135/tcp. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 10 Jun 2020
    7.8
    High

    CVE-2020-7586

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A buffer overflow vulnerability could allow a local attacker to cause a Denial-of-Service situation. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise the availability of the system as well as to have access to confidential information.

    Published: 10 Jun 2020
    7.8
    High

    CVE-2020-7585

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise the availability of the system as well as to have access to confidential information.

    Published: 10 Jun 2020
    7.5
    High

    CVE-2020-7670

    Last Modified: 21 Nov 2024

    agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing. It is possible to conduct HTTP request smuggling attacks where `agoo` is used as part of a chain of backend servers due to insufficient `Content-Length` and `Transfer Encoding` parsing.

    Published: 10 Jun 2020
    7.5
    High

    CVE-2020-7671

    Last Modified: 21 Nov 2024

    goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks.

    Published: 10 Jun 2020