CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2020-10612

    Last Modified: 21 Nov 2024

    Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open without any restrictions. This allows an attacker with network access to control the SoftPACAgent service including updating SoftPAC firmware, starting or stopping service, or writing to certain registry values.

    Published: 14 May 2020
    5.7
    Medium

    CVE-2020-12046

    Last Modified: 21 Nov 2024

    Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious files.

    Published: 14 May 2020
    6.5
    Medium

    CVE-2020-12068

    Last Modified: 21 Nov 2024

    An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.

    Published: 14 May 2020
    6.5
    Medium

    CVE-2020-12042

    Last Modified: 21 Nov 2024

    Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.

    Published: 14 May 2020
    —
    Unknown

    CVE-2020-12440

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 May 2020
    9.8
    Critical

    CVE-2020-0221

    Last Modified: 21 Nov 2024

    Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation could potentially return a pointer within the previous allocation's memory, which could lead to improper memory access.Product: AndroidVersions: Android kernelAndroid ID: A-135772851

    Published: 14 May 2020
    6.7
    Medium

    CVE-2020-0220

    Last Modified: 21 Nov 2024

    In crus_afe_callback of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-139739561

    Published: 14 May 2020
    5.5
    Medium

    CVE-2020-0100

    Last Modified: 21 Nov 2024

    In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. This could lead to local information disclosure of data from a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-8.0Android ID: A-150156584

    Published: 14 May 2020
    5.5
    Medium

    CVE-2020-0064

    Last Modified: 21 Nov 2024

    An improper authorization while processing the provisioning data.Product: AndroidVersions: Android SoCAndroid ID: A-149866855

    Published: 14 May 2020
    5.5
    Medium

    CVE-2020-0065

    Last Modified: 21 Nov 2024

    An improper authorization in the receiver component of the Android Suite Daemon.Product: AndroidVersions: Android SoCAndroid ID: A-149813448

    Published: 14 May 2020
    5.5
    Medium

    CVE-2020-0090

    Last Modified: 21 Nov 2024

    An improper authorization in the receiver component of Email.Product: AndroidVersions: Android SoCAndroid ID: A-149813048

    Published: 14 May 2020
    5.5
    Medium

    CVE-2020-0091

    Last Modified: 21 Nov 2024

    In mnld, an incorrect configuration in driver_cfg of mnld for meta factory mode.Product: AndroidVersions: Android SoCAndroid ID: A-149808700

    Published: 14 May 2020
    5.5
    Medium

    CVE-2020-0106

    Last Modified: 21 Nov 2024

    In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-148414207

    Published: 14 May 2020
    7.8
    High

    CVE-2020-0094

    Last Modified: 21 Nov 2024

    In setImageHeight and setImageWidth of ExifUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-148223871

    Published: 14 May 2020
    9.8
    Critical

    CVE-2020-0103

    Last Modified: 21 Nov 2024

    In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-148107188

    Published: 14 May 2020
    7.8
    High

    CVE-2020-0109

    Last Modified: 21 Nov 2024

    In simulatePackageSuspendBroadcast of NotificationManagerService.java, there is a missing permission check. This could lead to local escalation of privilege by creating fake system notifications with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-148059175

    Published: 14 May 2020
    7.8
    High

    CVE-2020-0097

    Last Modified: 21 Nov 2024

    In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead to local escalation of privilege with User privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-145981139

    Published: 14 May 2020
    7.8
    High

    CVE-2020-0096

    Last Modified: 21 Nov 2024

    In startActivities of ActivityStartController.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-145669109

    Published: 14 May 2020
    5
    Medium

    CVE-2020-0092

    Last Modified: 21 Nov 2024

    In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification content due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145135488

    Published: 14 May 2020
    5.5
    Medium

    CVE-2020-0101

    Last Modified: 21 Nov 2024

    In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144767096

    Published: 14 May 2020
    5.5
    Medium

    CVE-2020-0104

    Last Modified: 21 Nov 2024

    In onShowingStateChanged of KeyguardStateMonitor.java, there is a possible inappropriate read due to a logic error. This could lead to local information disclosure of keyguard-protected data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-144430870

    Published: 14 May 2020
    7.8
    High

    CVE-2020-0098

    Last Modified: 21 Nov 2024

    In navigateUpToLocked of ActivityStack.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-144285917

    Published: 14 May 2020
    7.8
    High

    CVE-2020-0105

    Last Modified: 21 Nov 2024

    In onKeyguardVisibilityChanged of key_store_service.cpp, there is a missing permission check. This could lead to local escalation of privilege, allowing apps to use keyguard-bound keys when the screen is locked, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-144285084

    Published: 14 May 2020
    7.8
    High

    CVE-2020-0102

    Last Modified: 21 Nov 2024

    In GattServer::SendResponse of gatt_server.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143231677

    Published: 14 May 2020
    7.8
    High

    CVE-2020-0024

    Last Modified: 21 Nov 2024

    In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-137015265

    Published: 14 May 2020
    9.8
    Critical

    CVE-2020-12874

    Last Modified: 21 Nov 2024

    Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server.

    Published: 14 May 2020
    6.3
    Medium

    CVE-2020-12875

    Last Modified: 21 Nov 2024

    Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitive information or functionality by manipulating specific parameters within the application.

    Published: 14 May 2020
    7.5
    High

    CVE-2020-12877

    Last Modified: 21 Nov 2024

    Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication.

    Published: 14 May 2020
    7.5
    High

    CVE-2020-12876

    Last Modified: 21 Nov 2024

    Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments.

    Published: 14 May 2020
    6.1
    Medium

    CVE-2020-12677

    Last Modified: 21 Nov 2024

    An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS. This affects 2018 - 2018.0 prior to 2018.0.3, 2018 SP1 - 2018.2 prior to 2018.2.3, 2018 SP2 - 2018.3 prior to 2018.3.7, 2019 - 2019.0 prior to 2019.0.3, 2019.1 - 2019.1 prior to 2019.1.2, and 2019.2 - 2019.2 prior to 2019.2.2.

    Published: 14 May 2020
    6.5
    Medium

    CVE-2020-5408

    Last Modified: 21 Nov 2024

    Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

    Published: 14 May 2020
    6.5
    Medium

    CVE-2019-13023

    Last Modified: 21 Nov 2024

    An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, and SNMP strings from 'non administrative' users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the credentials are visible.

    Published: 14 May 2020
    9.8
    Critical

    CVE-2019-13022

    Last Modified: 21 Nov 2024

    Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). It XORs the plaintext into the 'encrypted' password that is then stored within the database. These steps are able to be trivially reversed, allowing for escalation of privilege within the JetSelect application through obtaining the passwords of JetSelect administrators. JetSelect administrators have the ability to modify and delete all networking configuration across a vessel, as well as altering network configuration of all managed network devices (switches, routers).

    Published: 14 May 2020
    6.5
    Medium

    CVE-2019-13021

    Last Modified: 21 Nov 2024

    The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passwords is made as part of the installation script, after the administrator has generated a password using ENCtool.jar (see CVE-2019-13022). This allows any low-privilege user who can read this file to trivially obtain the passwords for the administrative accounts of the JetSelect application. The path to the file containing the encoded password hash is /opt/JetSelect/SFC/resources/sfc-general-properties.

    Published: 14 May 2020
    9.8
    Critical

    CVE-2019-17562

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an arbitrary shell command into the mac parameter, v-router will process the command. For example: Normal: http://{GW}:10086/baremetal/provisiondone/{mac}, Abnormal: http://{GW}:10086/baremetal/provisiondone/#';whoami;#. Mitigation of this issue is an upgrade to Apache CloudStack 4.13.1.0 or beyond.

    Published: 14 May 2020
    5.3
    Medium

    CVE-2019-17572

    Last Modified: 21 Nov 2024

    In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-10626

    Last Modified: 21 Nov 2024

    In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same name of any resident DLLs inside the software installation to execute arbitrary code.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4468

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by memory corruption. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash. IBM X-Force ID: 181723.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4467

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by memory corruption. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash. IBM X-Force ID: 181721.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4422

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 180167.

    Published: 14 May 2020
    4.3
    Medium

    CVE-2020-4365

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4343

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 178244.

    Published: 14 May 2020
    4.3
    Medium

    CVE-2020-4299

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4288

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash. IBM X-Force ID: 176270.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4287

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash. IBM X-Force ID: 176269.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4285

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash. IBM X-Force ID: 176266

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4266

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175649.

    Published: 14 May 2020
    7.3
    High

    CVE-2020-4265

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175648.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4264

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175647.

    Published: 14 May 2020
    7.8
    High

    CVE-2020-4263

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 175646.

    Published: 14 May 2020