CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2020-6435

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

    Published: 7 Apr 2020
    4.3
    Medium

    CVE-2020-6438

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.

    Published: 7 Apr 2020
    4.3
    Medium

    CVE-2020-6440

    Last Modified: 21 Nov 2024

    Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

    Published: 7 Apr 2020
    6.5
    Medium

    CVE-2020-6446

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 7 Apr 2020
    6.5
    Medium

    CVE-2020-6456

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.

    Published: 7 Apr 2020
    7.1
    High

    CVE-2020-10709

    Last Modified: 21 Nov 2024

    A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The original token granted to the user still has access to Ansible Tower, which allows any user that can gain access to the token to be fully authenticated to Ansible Tower. This flaw affects Ansible Tower versions before 3.6.4 and Ansible Tower versions before 3.5.6.

    Published: 7 Apr 2020
    7.8
    High

    CVE-2020-11560

    Last Modified: 21 Nov 2024

    NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.

    Published: 7 Apr 2020
    3.3
    Low

    CVE-2020-11869

    Last Modified: 21 Nov 2024

    An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6419

    Last Modified: 21 Nov 2024

    Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6430

    Last Modified: 21 Nov 2024

    Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Apr 2020
    4.3
    Medium

    CVE-2020-6431

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 7 Apr 2020
    4.3
    Medium

    CVE-2020-6432

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6436

    Last Modified: 21 Nov 2024

    Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Apr 2020
    4.3
    Medium

    CVE-2020-6437

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.

    Published: 7 Apr 2020
    4.3
    Medium

    CVE-2020-6441

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.

    Published: 7 Apr 2020
    4.3
    Medium

    CVE-2020-6442

    Last Modified: 21 Nov 2024

    Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6443

    Last Modified: 21 Nov 2024

    Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to execute arbitrary code via a crafted HTML page.

    Published: 7 Apr 2020
    6.3
    Medium

    CVE-2020-6444

    Last Modified: 21 Nov 2024

    Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6447

    Last Modified: 21 Nov 2024

    Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6448

    Last Modified: 21 Nov 2024

    Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6455

    Last Modified: 21 Nov 2024

    Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Apr 2020
    4.3
    Medium

    CVE-2020-6433

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6439

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.

    Published: 7 Apr 2020
    6.5
    Medium

    CVE-2020-6445

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6454

    Last Modified: 21 Nov 2024

    Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2020-11586

    Last Modified: 21 Nov 2024

    An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-11587

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the content of ETL Processes running on the server.

    Published: 6 Apr 2020
    5.3
    Medium

    CVE-2020-11588

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to two files that contain customer data and application paths.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-11589

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users only.

    Published: 6 Apr 2020
    5.3
    Medium

    CVE-2020-11590

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to HealthPage.aspx and obtain the internal server name.

    Published: 6 Apr 2020
    5.3
    Medium

    CVE-2020-11591

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the full application path along with the customer name.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-11592

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the columns of a specific table within the CIP database.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-11593

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-11594

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown providing the full file path.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-11595

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the upload folder path that includes the hostname in a UNC path.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-11596

    Last Modified: 21 Nov 2024

    A Directory Traversal issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make HTTP GET requests to a certain URL and obtain information about what files and directories reside on the server.

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-11597

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the user context of the db owner.

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-11598

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-11599

    Last Modified: 21 Nov 2024

    An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the username and password of the SMTP user.

    Published: 6 Apr 2020
    4.3
    Medium

    CVE-2020-11585

    Last Modified: 21 Nov 2024

    There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter.

    Published: 6 Apr 2020
    8.1
    High

    CVE-2020-11581

    Last Modified: 21 Nov 2024

    An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to the doCustomRemediateInstructions method, because Runtime.getRuntime().exec() is used.

    Published: 6 Apr 2020
    8.8
    High

    CVE-2020-11582

    Last Modified: 21 Nov 2024

    An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local connections on a random port. This can be reached by local HTTP clients, because up to 25 invalid lines are ignored, and because DNS rebinding can occur. (This server accepts, for example, a setcookie command that might be relevant to CVE-2020-11581 exploitation.)

    Published: 6 Apr 2020
    9.1
    Critical

    CVE-2020-11580

    Last Modified: 21 Nov 2024

    An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.

    Published: 6 Apr 2020
    7.8
    High

    CVE-2020-5832

    Last Modified: 21 Nov 2024

    Symantec Data Center Security Manager Component, prior to 6.8.2 (aka 6.8 MP2), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

    Published: 6 Apr 2020
    5.8
    Medium

    CVE-2020-1760

    Last Modified: 21 Nov 2024

    A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

    Published: 6 Apr 2020
    6.4
    Medium

    CVE-2020-1759

    Last Modified: 21 Nov 2024

    A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.

    Published: 6 Apr 2020
    5.8
    Medium

    CVE-2020-5300

    Last Modified: 21 Nov 2024

    In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, when using client authentication method 'private_key_jwt' [1], OpenId specification says the following about assertion `jti`: "A unique identifier for the token, which can be used to prevent reuse of the token. These tokens MUST only be used once, unless conditions for reuse were negotiated between the parties". Hydra does not check the uniqueness of this `jti` value. Exploiting this vulnerability is somewhat difficult because: - TLS protects against MITM which makes it difficult to intercept valid tokens for replay attacks - The expiry time of the JWT gives only a short window of opportunity where it could be replayed This has been patched in version v1.4.0+oryOS.17

    Published: 6 Apr 2020
    6.5
    Medium

    CVE-2020-8834

    Last Modified: 21 Nov 2024

    KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to panic. There were two commits that, according to the reporter, introduced the vulnerability: f024ee098476 ("KVM: PPC: Book3S HV: Pull out TM state save/restore into separate procedures") 87a11bb6a7f7 ("KVM: PPC: Book3S HV: Work around XER[SO] bug in fake suspend mode") The former landed in 4.8, the latter in 4.17. This was fixed without realizing the impact in 4.18 with the following three commits, though it's believed the first is the only strictly necessary commit: 6f597c6b63b6 ("KVM: PPC: Book3S PR: Add guest MSR parameter for kvmppc_save_tm()/kvmppc_restore_tm()") 7b0e827c6970 ("KVM: PPC: Book3S HV: Factor fake-suspend handling out of kvmppc_save/restore_tm") 009c872a8bc4 ("KVM: PPC: Book3S PR: Move kvmppc_save_tm/kvmppc_restore_tm to separate file")

    Published: 6 Apr 2020
    7.8
    High

    CVE-2020-11507

    Last Modified: 21 Nov 2024

    An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded.

    Published: 6 Apr 2020
    7.2
    High

    CVE-2019-19699

    Last Modified: 21 Nov 2024

    There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a custom main.php?p=60803&type=3 command. The user must then set the Pollers Post-Restart Command to this previously created command via the main.php?p=60901&o=c&server_id=1 URI. This is triggered via an export of the Poller Configuration.

    Published: 6 Apr 2020