CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2018-20586

    Last Modified: 21 Nov 2024

    bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.

    Published: 12 Mar 2020
    5.3
    Medium

    CVE-2018-19516

    Last Modified: 21 Nov 2024

    messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.

    Published: 12 Mar 2020
    6.1
    Medium

    CVE-2018-10704

    Last Modified: 21 Nov 2024

    yidashi yii2cmf 2.0 has XSS via the /search q parameter.

    Published: 12 Mar 2020
    5.9
    Medium

    CVE-2017-18350

    Last Modified: 21 Nov 2024

    bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server responds with an acknowledgement of an unexpected target domain name.

    Published: 12 Mar 2020
    6.7
    Medium

    CVE-2020-0526

    Last Modified: 21 Nov 2024

    Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0520

    Last Modified: 21 Nov 2024

    Path traversal in igdkmd64.sys for Intel(R) Graphics Drivers before versions 15.45.30.5103, 15.40.44.5107, 15.36.38.5117 and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-5961

    Last Modified: 21 Nov 2024

    NVIDIA vGPU graphics driver for guest OS contains a vulnerability in which an incorrect resource clean up on a failure path can impact the guest VM, leading to denial of service.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-5959

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin in which an input index value is incorrectly validated which may lead to denial of service.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-5960

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the kernel module (nvidia.ko), where a null pointer dereference may occur, which may lead to denial of service.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0519

    Last Modified: 21 Nov 2024

    Improper access control for Intel(R) Graphics Drivers before versions 15.33.49.5100 and 15.36.38.5117 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access.

    Published: 12 Mar 2020
    5.3
    Medium

    CVE-2020-0517

    Last Modified: 21 Nov 2024

    Out-of-bounds write in Intel(R) Graphics Drivers before version 15.36.38.5117 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-0516

    Last Modified: 21 Nov 2024

    Improper access control in Intel(R) Graphics Drivers before version 26.20.100.7463 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0515

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7584, 15.45.30.5103, 15.40.44.5107, 15.36.38.5117, and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege via local access

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0514

    Last Modified: 21 Nov 2024

    Improper default permissions in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7463 and 15.45.30.5103 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-0511

    Last Modified: 21 Nov 2024

    Uncaught exception in system driver for Intel(R) Graphics Drivers before version 15.40.44.5107 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0508

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the installer for Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Mar 2020
    7.5
    High

    CVE-2020-10532

    Last Modified: 21 Nov 2024

    The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-0503

    Last Modified: 21 Nov 2024

    Improper access control in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 12 Mar 2020
    6.1
    Medium

    CVE-2020-0505

    Last Modified: 21 Nov 2024

    Improper conditions check in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable information disclosure and denial of service via local

    Published: 12 Mar 2020
    4.4
    Medium

    CVE-2019-14625

    Last Modified: 21 Nov 2024

    Improper access control in on-card storage for the Intel® FPGA Programmable Acceleration Card N3000, all versions, may allow a privileged user to potentially enable denial of service via local access.

    Published: 12 Mar 2020
    6.7
    Medium

    CVE-2019-14626

    Last Modified: 21 Nov 2024

    Improper access control in PCIe function for the Intel® FPGA Programmable Acceleration Card N3000, all versions, may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-0501

    Last Modified: 21 Nov 2024

    Buffer overflow in Intel(R) Graphics Drivers before version 26.20.100.6912 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 12 Mar 2020
    5.3
    Medium

    CVE-2020-0502

    Last Modified: 21 Nov 2024

    Improper access control in Intel(R) Graphics Drivers before version 26.20.100.6912 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0504

    Last Modified: 21 Nov 2024

    Buffer overflow in Intel(R) Graphics Drivers before versions 15.40.44.5107, 15.45.30.5103, and 26.20.100.7158 may allow an authenticated user to potentially enable escalation of privilege and denial of service via local access.

    Published: 12 Mar 2020
    2.3
    Low

    CVE-2020-0506

    Last Modified: 21 Nov 2024

    Improper initialization in Intel(R) Graphics Drivers before versions 15.40.44.5107, 15.45.29.5077, and 26.20.100.7000 may allow a privileged user to potentially enable a denial of service via local access.

    Published: 12 Mar 2020
    4.4
    Medium

    CVE-2020-0507

    Last Modified: 21 Nov 2024

    Unquoted service path in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 12 Mar 2020
    8
    High

    CVE-2020-0905

    Last Modified: 21 Nov 2024

    An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.

    Published: 12 Mar 2020
    9.8
    Critical

    CVE-2020-0902

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'.

    Published: 12 Mar 2020
    5.4
    Medium

    CVE-2020-0903

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0897

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-0800, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0898

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0791.

    Published: 12 Mar 2020
    5.4
    Medium

    CVE-2020-0894

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0893.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0896

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0840, CVE-2020-0841, CVE-2020-0849.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0892

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.

    Published: 12 Mar 2020
    5.4
    Medium

    CVE-2020-0893

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0894.

    Published: 12 Mar 2020
    5.4
    Medium

    CVE-2020-0891

    Last Modified: 28 Feb 2025

    This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'. This CVE ID is unique from CVE-2020-0795.

    Published: 12 Mar 2020
    4.3
    Medium

    CVE-2020-0885

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows Graphics Component Information Disclosure Vulnerability'.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0887

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0877.

    Published: 12 Mar 2020
    3.7
    Low

    CVE-2020-0884

    Last Modified: 21 Nov 2024

    A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'.

    Published: 12 Mar 2020
    8.8
    High

    CVE-2020-0883

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0881.

    Published: 12 Mar 2020
    8.8
    High

    CVE-2020-0881

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0883.

    Published: 12 Mar 2020
    6.5
    Medium

    CVE-2020-0882

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2020-0880.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-0879

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0880, CVE-2020-0882.

    Published: 12 Mar 2020
    6.5
    Medium

    CVE-2020-0880

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2020-0882.

    Published: 12 Mar 2020
    7.8
    High

    CVE-2020-0877

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0887.

    Published: 12 Mar 2020
    7.5
    High

    CVE-2020-0876

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-0874

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0879, CVE-2020-0880, CVE-2020-0882.

    Published: 12 Mar 2020
    9.6
    Critical

    CVE-2020-0872

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'.

    Published: 12 Mar 2020
    5.5
    Medium

    CVE-2020-0871

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when Windows Network Connections Service fails to properly handle objects in memory, aka 'Windows Network Connections Service Information Disclosure Vulnerability'.

    Published: 12 Mar 2020
    8.8
    High

    CVE-2020-0869

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0809.

    Published: 12 Mar 2020