CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-8853

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9591.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8855

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.2947. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the fxhtml2pdf.exe module. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9560.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8851

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9406.

    Published: 13 Feb 2020
    3.3
    Low

    CVE-2020-8852

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPEG2000 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-9416.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8849

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPEG2000 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9413.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8850

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPEG2000 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9415.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8847

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPEG2000 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9414.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8848

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9407.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8846

    Last Modified: 21 Nov 2024

    This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of text field objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9400.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8845

    Last Modified: 21 Nov 2024

    This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of watermarks in AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9358.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8844

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG files within CovertToPDF. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9102.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2013-7173

    Last Modified: 21 Nov 2024

    Belkin n750 routers have a buffer overflow.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2013-7287

    Last Modified: 21 Nov 2024

    MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.

    Published: 13 Feb 2020
    6.5
    Medium

    CVE-2014-1617

    Last Modified: 21 Nov 2024

    Microsys PROMOTIC 8.2.13 contains an ActiveX Control Start Buffer Overflow vulnerability which can lead to denial of service.

    Published: 13 Feb 2020
    7.5
    High

    CVE-2013-1634

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller devices through 2013-02-06 where the device can be brought into a non-processing state when parsing 32 hex, 33 hex, or 34 hex byte values at the 0x47f offset. NOTE: A followup statement from Intel suggests that the root cause of this issue was an incorrectly configured EEPROM image.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2013-1401

    Last Modified: 21 Nov 2024

    Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.

    Published: 13 Feb 2020
    5.9
    Medium

    CVE-2020-8988

    Last Modified: 21 Nov 2024

    The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.

    Published: 13 Feb 2020
    5.3
    Medium

    CVE-2020-8989

    Last Modified: 21 Nov 2024

    In the Voatz application 2020-01-01 for Android, the amount of data transmitted during a single voter's vote depends on the different lengths of the metadata across the available voting choices, which makes it easier for remote attackers to discover this voter's choice by sniffing the network. For example, a small amount of sniffed data may indicate that a vote was cast for the candidate with the least metadata. An active man-in-the-middle attacker can leverage this behavior to disrupt voters' abilities to vote for a candidate opposed by the attacker.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2013-1400

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2015-6589

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient restrictions in file paths to json.ashx.

    Published: 13 Feb 2020
    5.5
    Medium

    CVE-2019-3998

    Last Modified: 21 Nov 2024

    Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi network the base station connects to.

    Published: 13 Feb 2020
    —
    Unknown

    CVE-2013-0295

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0342. Reason: This candidate is a duplicate of [ID]. Notes: All CVE users should reference CVE-2013-0342 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Feb 2020
    7.5
    High

    CVE-2015-3309

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE: This vulnerability is due to an incomplete fix to CVE-2015-3297.

    Published: 13 Feb 2020
    7.5
    High

    CVE-2014-3208

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery),

    Published: 13 Feb 2020
    7.5
    High

    CVE-2012-6091

    Last Modified: 21 Nov 2024

    Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.

    Published: 13 Feb 2020
    9.3
    Critical

    CVE-2014-3919

    Last Modified: 21 Nov 2024

    A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2014-4170

    Last Modified: 21 Nov 2024

    A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.

    Published: 13 Feb 2020
    7.5
    High

    CVE-2012-5623

    Last Modified: 21 Nov 2024

    Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.

    Published: 13 Feb 2020
    9.1
    Critical

    CVE-2014-4198

    Last Modified: 21 Nov 2024

    A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID and AD parameters, which could let a malicious user access privileged function.

    Published: 13 Feb 2020
    6.7
    Medium

    CVE-2019-14598

    Last Modified: 21 Nov 2024

    Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-0561

    Last Modified: 21 Nov 2024

    Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-0562

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-0563

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for Intel(R) MPSS before version 3.8.6 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-0564

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Feb 2020
    6.1
    Medium

    CVE-2020-8981

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_delete.php Delete Repository page allows execution of arbitrary code via a repo name (if CSP settings permit it). This is related to CVE-2018-16362.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-0560

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Feb 2020
    5.4
    Medium

    CVE-2012-1903

    Last Modified: 21 Nov 2024

    XSS in Telligent Community 5.6.583.20496 via a flash file and related to the allowScriptAccess parameter.

    Published: 13 Feb 2020
    5.4
    Medium

    CVE-2012-1500

    Last Modified: 21 Nov 2024

    Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.

    Published: 13 Feb 2020
    6.1
    Medium

    CVE-2019-10785

    Last Modified: 21 Nov 2024

    dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.

    Published: 13 Feb 2020
    7.5
    High

    CVE-2020-3741

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5, and 6.4 have an uncontrolled resource consumption vulnerability. Successful exploitation could lead to denial-of-service.

    Published: 13 Feb 2020
    7.5
    High

    CVE-2020-3759

    Last Modified: 21 Nov 2024

    Adobe Digital Editions versions 4.5.10 and below have a buffer errors vulnerability. Successful exploitation could lead to information disclosure.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-3760

    Last Modified: 21 Nov 2024

    Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-3750

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-3754

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-3752

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-3745

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-3751

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 13 Feb 2020
    7.5
    High

    CVE-2020-3755

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 13 Feb 2020
    7.5
    High

    CVE-2020-3753

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to memory leak .

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-3749

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 13 Feb 2020