CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-8036

    Last Modified: 21 Nov 2024

    The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.

    Published: 29 Feb 2020
    8.8
    High

    CVE-2020-6804

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication token. When combined with CVE-2020-6803, an attacker could fully compromise the system.

    Published: 28 Feb 2020
    5.4
    Medium

    CVE-2020-6803

    Last Modified: 21 Nov 2024

    An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.

    Published: 28 Feb 2020
    6.5
    Medium

    CVE-2015-3006

    Last Modified: 21 Nov 2024

    On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after the system has been up and running for some time, but immediately after boot, the entropy is very low. This issue only affects the QFX3500 and QFX3600 switches. No other Juniper Networks products or platforms are affected by this weak entropy vulnerability.

    Published: 28 Feb 2020
    6.5
    Medium

    CVE-2015-5361

    Last Modified: 21 Nov 2024

    Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open related sessions for the FTP data channel. These related sessions (gates) are specific to source and destination IPs and ports of client and server. The design intent of the ftps-extensions option (which is disabled by default) is to provide similar functionality when the SRX secures the FTP/FTPS client. As the control channel is encrypted, the FTP ALG cannot inspect the port specific information and will open a wider TCP data channel (gate) from client IP to server IP on all destination TCP ports. In FTP/FTPS client environments to an enterprise network or the Internet, this is the desired behavior as it allows firewall policy to be written to FTP/FTPS servers on well-known control ports without using a policy with destination IP ANY and destination port ANY. Issue The ftps-extensions option is not intended or recommended where the SRX secures the FTPS server, as the wide data channel session (gate) will allow the FTPS client temporary access to all TCP ports on the FTPS server. The data session is associated to the control channel and will be closed when the control channel session closes. Depending on the configuration of the FTPS server, supporting load-balancer, and SRX inactivity-timeout values, the server/load-balancer and SRX may keep the control channel open for an extended period of time, allowing an FTPS client access for an equal duration.​ Note that the ftps-extensions option is not enabled by default.

    Published: 28 Feb 2020
    7.5
    High

    CVE-2019-7007

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server.

    Published: 28 Feb 2020
    8.4
    High

    CVE-2019-4301

    Last Modified: 21 Nov 2024

    BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Running Message or Post Message HTML.

    Published: 28 Feb 2020
    5.4
    Medium

    CVE-2020-9459

    Last Modified: 21 Nov 2024

    Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote authenticated users (with minimal permissions) to inject arbitrary JavaScript, HTML, or CSS via Ajax actions. This affects mec_save_notifications and import_settings.

    Published: 28 Feb 2020
    9.8
    Critical

    CVE-2019-10801

    Last Modified: 21 Nov 2024

    enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.

    Published: 28 Feb 2020
    9.8
    Critical

    CVE-2019-10802

    Last Modified: 21 Nov 2024

    giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package without any validation.

    Published: 28 Feb 2020
    9.8
    Critical

    CVE-2019-10803

    Last Modified: 21 Nov 2024

    push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being provided to the "git" command within "index.js#L139". This could be abused by an attacker to inject arbitrary commands.

    Published: 28 Feb 2020
    9.8
    Critical

    CVE-2019-10804

    Last Modified: 21 Nov 2024

    serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the "exec" function without any validation.

    Published: 28 Feb 2020
    7.5
    High

    CVE-2019-10805

    Last Modified: 21 Nov 2024

    valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks.

    Published: 28 Feb 2020
    8.8
    High

    CVE-2020-9449

    Last Modified: 21 Nov 2024

    An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (client) version 19.11 allows an attacker (with a guest or user session cookie) to escalate privileges by retrieving the cookie salt value and creating a valid session cookie for an arbitrary user or admin.

    Published: 28 Feb 2020
    6.1
    Medium

    CVE-2020-9466

    Last Modified: 21 Nov 2024

    The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.

    Published: 28 Feb 2020
    7.5
    High

    CVE-2019-19943

    Last Modified: 21 Nov 2024

    The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.

    Published: 28 Feb 2020
    9.8
    Critical

    CVE-2020-9465

    Last Modified: 21 Nov 2024

    An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the user_id field in a cookie.

    Published: 28 Feb 2020
    9.8
    Critical

    CVE-2019-15609

    Last Modified: 21 Nov 2024

    The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.

    Published: 28 Feb 2020
    6.1
    Medium

    CVE-2020-8127

    Last Modified: 21 Nov 2024

    Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.

    Published: 28 Feb 2020
    9.8
    Critical

    CVE-2020-8132

    Last Modified: 21 Nov 2024

    Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.

    Published: 28 Feb 2020
    5.5
    Medium

    CVE-2020-1792

    Last Modified: 21 Nov 2024

    Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0.0.146(C432E4R1P4) have an out of bounds write vulnerability. The software writes data past the end of the intended buffer because of insufficient validation of certain parameter when initializing certain driver program. An attacker could trick the user into installing a malicious application, successful exploit could cause the device to reboot.

    Published: 28 Feb 2020
    7.8
    High

    CVE-2020-1844

    Last Modified: 21 Nov 2024

    PCManager with versions earlier than 10.0.5.51 have a privilege escalation vulnerability in Huawei PCManager products. An authenticated, local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege.

    Published: 28 Feb 2020
    4.4
    Medium

    CVE-2020-1877

    Last Modified: 21 Nov 2024

    NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when administrator log in to the device and performs some operations. Successful exploit could cause certain process reboot.

    Published: 28 Feb 2020
    7.5
    High

    CVE-2020-1876

    Last Modified: 21 Nov 2024

    NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds write vulnerability. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot.

    Published: 28 Feb 2020
    4.4
    Medium

    CVE-2020-1861

    Last Modified: 21 Nov 2024

    CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V200R005C00SPC800PWE,V200R005C10,V200R005C10SPC300 have an information leakage vulnerability in some Huawei products. In some special cases, an authenticated attacker can exploit this vulnerability because the software processes data improperly. Successful exploitation may lead to information leakage.

    Published: 28 Feb 2020
    7.5
    High

    CVE-2020-1881

    Last Modified: 21 Nov 2024

    NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have have a resource management error vulnerability. An attacker needs to perform specific operations to trigger a function of the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal on affected devices.

    Published: 28 Feb 2020
    7.5
    High

    CVE-2020-1860

    Last Modified: 21 Nov 2024

    NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an access control bypass vulnerability. Attackers that can access to the internal network can exploit this vulnerability with careful deployment. Successful exploit may cause the access control to be bypassed, and attackers can directly access the Internet.

    Published: 28 Feb 2020
    5.5
    Medium

    CVE-2020-1874

    Last Modified: 21 Nov 2024

    NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid pointer access vulnerability. The software system access an invalid pointer when operator logs in to the device and performs some operations. Successful exploit could cause certain process reboot.

    Published: 28 Feb 2020
    7.5
    High

    CVE-2020-1873

    Last Modified: 21 Nov 2024

    NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds read vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the device reboot.

    Published: 28 Feb 2020
    5.5
    Medium

    CVE-2020-1875

    Last Modified: 21 Nov 2024

    NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when an abnormal condition occurs in certain operation. Successful exploit could cause certain process reboot. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500;USG9500 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500.

    Published: 28 Feb 2020
    8.8
    High

    CVE-2020-9463

    Last Modified: 21 Nov 2024

    Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.

    Published: 28 Feb 2020
    6.5
    Medium

    CVE-2020-5247

    Last Modified: 21 Nov 2024

    In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as additional headers or an entirely new response body. This vulnerability is known as HTTP Response Splitting. While not an attack in itself, response splitting is a vector for several other attacks, such as cross-site scripting (XSS). This is related to CVE-2019-16254, which fixed this vulnerability for the WEBrick Ruby web server. This has been fixed in versions 4.3.2 and 3.12.3 by checking all headers for line endings and rejecting headers with those characters.

    Published: 28 Feb 2020
    6.1
    Medium

    CVE-2020-9447

    Last Modified: 21 Nov 2024

    There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attackers to steal data, change the appearance of a website, and perform other malicious activities like phishing or drive-by hacking.

    Published: 28 Feb 2020
    5.5
    Medium

    CVE-2020-9399

    Last Modified: 21 Nov 2024

    The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 definitions 200114-0 of Antivirus Pro, Antivirus Pro Plus, and Antivirus for Linux.

    Published: 28 Feb 2020
    7.8
    High

    CVE-2020-9442

    Last Modified: 21 Nov 2024

    OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.

    Published: 28 Feb 2020
    5.7
    Medium

    CVE-2019-3698

    Last Modified: 21 Nov 2024

    UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11 nagios version 3.0.6-1.25.36.3.1 and prior versions. openSUSE Factory nagios version 4.4.5-2.1 and prior versions.

    Published: 28 Feb 2020
    7.5
    High

    CVE-2019-8741

    Last Modified: 21 Nov 2024

    A denial of service issue was addressed with improved input validation.

    Published: 28 Feb 2020
    5
    Medium

    CVE-2020-1746

    Last Modified: 21 Nov 2024

    A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if a playbook task is written using the bind_pw in the parameters field. The highest threat from this vulnerability is data confidentiality.

    Published: 28 Feb 2020
    9.8
    Critical

    CVE-2020-10188

    Last Modified: 21 Jan 2026

    utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.

    Published: 28 Feb 2020
    9.1
    Critical

    CVE-2020-9432

    Last Modified: 21 Nov 2024

    openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

    Published: 27 Feb 2020
    9.1
    Critical

    CVE-2020-9433

    Last Modified: 21 Nov 2024

    openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

    Published: 27 Feb 2020
    9.1
    Critical

    CVE-2020-9434

    Last Modified: 21 Nov 2024

    openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.

    Published: 27 Feb 2020
    7.5
    High

    CVE-2020-9429

    Last Modified: 21 Nov 2024

    In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.

    Published: 27 Feb 2020
    5.3
    Medium

    CVE-2018-8878

    Last Modified: 21 Nov 2024

    Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

    Published: 27 Feb 2020
    5.3
    Medium

    CVE-2018-8877

    Last Modified: 21 Nov 2024

    Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3854

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.3. An application may be able to execute arbitrary code with system privileges.

    Published: 27 Feb 2020
    7.1
    High

    CVE-2020-3861

    Last Modified: 21 Nov 2024

    The issue was addressed with improved permissions logic. This issue is fixed in iTunes for Windows 12.10.4. A user may gain access to protected parts of the file system.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3870

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 27 Feb 2020
    5.5
    Medium

    CVE-2020-3875

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.

    Published: 27 Feb 2020
    7.8
    High

    CVE-2020-3856

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. Processing a maliciously crafted string may lead to heap corruption.

    Published: 27 Feb 2020