CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2020-3204

    Last Modified: 21 Nov 2024

    A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by loading malicious Tcl code on an affected device. A successful exploit could allow the attacker to cause memory corruption or execute the code with root privileges on the underlying OS of the affected device.

    Published: 3 Jun 2020
    8.6
    High

    CVE-2020-3203

    Last Modified: 21 Nov 2024

    A vulnerability in the locally significant certificate (LSC) provisioning feature of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak that could lead to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain public key infrastructure (PKI) packets. An attacker could exploit this vulnerability by sending crafted Secure Sockets Layer (SSL) packets to an affected device. A successful exploit could cause an affected device to continuously consume memory, which could result in a memory allocation failure that leads to a crash and causes a DoS condition.

    Published: 3 Jun 2020
    6
    Medium

    CVE-2020-3201

    Last Modified: 21 Nov 2024

    A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by executing crafted Tcl arguments on an affected device. An exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

    Published: 3 Jun 2020
    3.3
    Low

    CVE-2020-3322

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file.

    Published: 3 Jun 2020
    3.3
    Low

    CVE-2020-3321

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file.

    Published: 3 Jun 2020
    3.3
    Low

    CVE-2020-3319

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file. This vulnerability affects Cisco Webex Network Recording Player and Webex Player releases earlier than Release 3.0 MR3 Security Patch 2 and 4.0 MR3.

    Published: 3 Jun 2020
    7.5
    High

    CVE-2019-20809

    Last Modified: 21 Nov 2024

    The price oracle in PriceOracle.sol in Compound Finance Compound Price Oracle 1.0 through 2.0 allows a price poster to set an invalid asset price via the setPrice function, and consequently violate the intended limits on price swings.

    Published: 3 Jun 2020
    5.9
    Medium

    CVE-2020-4035

    Last Modified: 21 Nov 2024

    In WatermelonDB (NPM package "@nozbe/watermelondb") before versions 0.15.1 and 0.16.2, a maliciously crafted record ID can exploit a SQL Injection vulnerability in iOS adapter implementation and cause the app to delete all or selected records from the database, generally causing the app to become unusable. This may happen in apps that don't validate IDs (valid IDs are `/^[a-zA-Z0-9_-.]+$/`) and use Watermelon Sync or low-level `database.adapter.destroyDeletedRecords` method. The integrity risk is low due to the fact that maliciously deleted records won't synchronize, so logout-login will restore all data, although some local changes may be lost if the malicious deletion causes the sync process to fail to proceed to push stage. No way to breach confidentiality with this vulnerability is known. Full exploitation of SQL Injection is mitigated, because it's not possible to nest an insert/update query inside a delete query in SQLite, and it's not possible to pass a semicolon-separated second query. There's also no known practicable way to breach confidentiality by selectively deleting records, because those records will not be synchronized. It's theoretically possible that selective record deletion could cause an app to behave insecurely if lack of a record is used to make security decisions by the app. This is patched in versions 0.15.1, 0.16.2, and 0.16.1-fix

    Published: 3 Jun 2020
    —
    Unknown

    CVE-2019-19214

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none

    Published: 3 Jun 2020
    6
    Medium

    CVE-2020-13597

    Last Modified: 21 Nov 2024

    Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromised pod with sufficient privilege is able to reconfigure the node’s IPv6 interface due to the node accepting route advertisement by default, allowing the attacker to redirect full or partial network traffic from the node to the compromised pod.

    Published: 3 Jun 2020
    —
    Unknown

    CVE-2019-19213

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none

    Published: 3 Jun 2020
    8.8
    High

    CVE-2020-13782

    Last Modified: 21 Nov 2024

    D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

    Published: 3 Jun 2020
    7.5
    High

    CVE-2020-13783

    Last Modified: 21 Nov 2024

    D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.

    Published: 3 Jun 2020
    7.5
    High

    CVE-2020-13784

    Last Modified: 21 Nov 2024

    D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.

    Published: 3 Jun 2020
    7.5
    High

    CVE-2020-13785

    Last Modified: 21 Nov 2024

    D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.

    Published: 3 Jun 2020
    8.8
    High

    CVE-2020-13786

    Last Modified: 21 Nov 2024

    D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.

    Published: 3 Jun 2020
    7.5
    High

    CVE-2020-13787

    Last Modified: 21 Nov 2024

    D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.

    Published: 3 Jun 2020
    8
    High

    CVE-2020-12846

    Last Modified: 21 Nov 2024

    Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is potential abuse of /service/upload servlet in the webmail subsystem. A user can upload executable files (exe,sh,bat,jar) in the Contact section of the mailbox as an avatar image for a contact. A user will receive a "Corrupt File" error, but the file is still uploaded and stored locally in /opt/zimbra/data/tmp/upload/, leaving it open to possible remote execution.

    Published: 3 Jun 2020
    6.5
    Medium

    CVE-2020-4307

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of service attack. IBM X-Force ID: 176997.

    Published: 3 Jun 2020
    6.7
    Medium

    CVE-2020-4190

    Last Modified: 21 Nov 2024

    IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174851.

    Published: 3 Jun 2020
    5.3
    Medium

    CVE-2020-4187

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system. IBM X-Force ID: 174805.

    Published: 3 Jun 2020
    6.1
    Medium

    CVE-2020-4182

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174738.

    Published: 3 Jun 2020
    8.8
    High

    CVE-2020-4180

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 174735.

    Published: 3 Jun 2020
    9.8
    Critical

    CVE-2020-4177

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174732.

    Published: 3 Jun 2020
    —
    Unknown

    CVE-2020-1703

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Red Hat Product Security does not consider this as a security flaw. Password changes aren't expected to invalidate existing sessions. Though this is how Kerberos behaves: incrementing kvno will not invalidate any existing service tickets. This is not a concern because the lifetime on service tickets should be set appropriately (initially only a global, now also more finely configurable with the kdcpolicy plugin). This belief is reinforced by our use of mod_session: existing sessions there aren't terminated, but instead wait for expiration

    Published: 3 Jun 2020
    9.8
    Critical

    CVE-2020-13756

    Last Modified: 3 Nov 2025

    Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.

    Published: 3 Jun 2020
    9.8
    Critical

    CVE-2020-10516

    Last Modified: 21 Nov 2024

    An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.21 and was fixed in 2.20.9, 2.19.15, and 2.18.20. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 3 Jun 2020
    9.1
    Critical

    CVE-2020-1963

    Last Modified: 21 Nov 2024

    Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.

    Published: 3 Jun 2020
    7.2
    High

    CVE-2020-7116

    Last Modified: 21 Nov 2024

    The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.

    Published: 3 Jun 2020
    7.2
    High

    CVE-2020-7117

    Last Modified: 21 Nov 2024

    The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.

    Published: 3 Jun 2020
    9.8
    Critical

    CVE-2020-7115

    Last Modified: 21 Nov 2024

    The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.

    Published: 3 Jun 2020
    8.8
    High

    CVE-2020-2200

    Last Modified: 21 Nov 2024

    Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master for a form validation endpoint, resulting in an OS command injection vulnerability exploitable by users able to store such a file on the Jenkins master.

    Published: 3 Jun 2020
    4.3
    Medium

    CVE-2020-2197

    Last Modified: 21 Nov 2024

    Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to access Inheritance Project job configurations in XML format.

    Published: 3 Jun 2020
    6.5
    Medium

    CVE-2020-2198

    Last Modified: 21 Nov 2024

    Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure.

    Published: 3 Jun 2020
    6.1
    Medium

    CVE-2020-2199

    Last Modified: 21 Nov 2024

    Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.

    Published: 3 Jun 2020
    5.4
    Medium

    CVE-2020-2195

    Last Modified: 21 Nov 2024

    Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission.

    Published: 3 Jun 2020
    8
    High

    CVE-2020-2196

    Last Modified: 21 Nov 2024

    Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin.

    Published: 3 Jun 2020
    5.4
    Medium

    CVE-2020-2193

    Last Modified: 21 Nov 2024

    Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in a stored cross-site scripting vulnerability.

    Published: 3 Jun 2020
    5.4
    Medium

    CVE-2020-2194

    Last Modified: 21 Nov 2024

    Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, resulting in a stored cross-site scripting vulnerability.

    Published: 3 Jun 2020
    4.3
    Medium

    CVE-2020-2191

    Last Modified: 21 Nov 2024

    Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that allow adding and removing agent labels.

    Published: 3 Jun 2020
    6.5
    Medium

    CVE-2020-2192

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove agent labels.

    Published: 3 Jun 2020
    9.4
    Critical

    CVE-2019-17638

    Last Modified: 21 Nov 2024

    In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice. Because of this double release, two threads can acquire the same ByteBuffer from the pool and while thread1 is about to use the ByteBuffer to write response1 data, thread2 fills the ByteBuffer with other data. Thread1 then proceeds to write the buffer that now contains different data. This results in client1, which issued request1 seeing data from another request or response which could contain sensitive data belonging to client2 (HTTP session ids, authentication credentials, etc.). If the Jetty version cannot be upgraded, the vulnerability can be significantly reduced by configuring a responseHeaderSize significantly larger than the requestHeaderSize (12KB responseHeaderSize and 8KB requestHeaderSize).

    Published: 3 Jun 2020
    6.5
    Medium

    CVE-2020-10755

    Last Modified: 21 Nov 2024

    An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO or VxFlex OS backend storage driver, credentials for the entire backend are exposed in the ``connection_info`` element in all Block Storage v3 Attachments API calls containing that element. This flaw enables an end-user to create a volume, make an API call to show the attachment detail information, and retrieve a username and password that may be used to connect to another user's volume. Additionally, these credentials are valid for the ScaleIO or VxFlex OS Management API, should an attacker discover the Management API endpoint. Source: OpenStack project

    Published: 3 Jun 2020
    5.9
    Medium

    CVE-2020-13254

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.

    Published: 3 Jun 2020
    8.2
    High

    CVE-2020-13379

    Last Modified: 21 Nov 2024

    The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

    Published: 3 Jun 2020
    5.4
    Medium

    CVE-2020-2190

    Last Modified: 21 Nov 2024

    Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.

    Published: 3 Jun 2020
    6.5
    Medium

    CVE-2020-6494

    Last Modified: 21 Nov 2024

    Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 3 Jun 2020
    8.8
    High

    CVE-2020-6496

    Last Modified: 21 Nov 2024

    Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 3 Jun 2020
    7
    High

    CVE-2020-29368

    Last Modified: 21 Nov 2024

    An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.

    Published: 3 Jun 2020
    5.4
    Medium

    CVE-2020-7015

    Last Modified: 21 Nov 2024

    Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, or perform destructive actions, on behalf of Kibana users who edit the TSVB visualization.

    Published: 3 Jun 2020