CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-8803

    Last Modified: 21 Nov 2024

    SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-8802

    Last Modified: 21 Nov 2024

    SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.

    Published: 13 Feb 2020
    7.2
    High

    CVE-2020-8801

    Last Modified: 21 Nov 2024

    SuiteCRM through 7.11.11 allows PHAR Deserialization.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-8800

    Last Modified: 21 Nov 2024

    SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-3742

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions, 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 13 Feb 2020
    5.4
    Medium

    CVE-2019-18791

    Last Modified: 21 Nov 2024

    Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3737

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3724

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3726

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3722

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3725

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3727

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3723

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-3740

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3732

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3729

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3730

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3731

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3728

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3733

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3736

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3738

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3739

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3735

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3721

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3734

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-3720

    Last Modified: 21 Nov 2024

    Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Feb 2020
    6.5
    Medium

    CVE-2020-0028

    Last Modified: 21 Nov 2024

    In notifyNetworkTested and related functions of NetworkMonitor.java, there is a possible bypass of private DNS settings. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-122652057

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-0027

    Last Modified: 21 Nov 2024

    In HidRawSensor::batch of HidRawSensor.cpp, there is a possible out of bounds write due to an unexpected switch fallthrough. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144040966

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-0026

    Last Modified: 21 Nov 2024

    In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140419401

    Published: 13 Feb 2020
    6.7
    Medium

    CVE-2020-0005

    Last Modified: 21 Nov 2024

    In btm_read_remote_ext_features_complete of btm_acl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-141552859

    Published: 13 Feb 2020
    5.5
    Medium

    CVE-2020-0023

    Last Modified: 21 Nov 2024

    In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluetooth connection, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145130871

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-0022

    Last Modified: 21 Nov 2024

    In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143894715

    Published: 13 Feb 2020
    6.5
    Medium

    CVE-2020-0021

    Last Modified: 21 Nov 2024

    In removeUnusedPackagesLPw of PackageManagerService.java, there is a possible permanent denial-of-service due to a missing package dependency test. This could lead to remote denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141413692

    Published: 13 Feb 2020
    5.5
    Medium

    CVE-2020-0020

    Last Modified: 21 Nov 2024

    In getAttributeRange of ExifInterface.java, there is a possible failure to redact location information from media files due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143118731

    Published: 13 Feb 2020
    4.4
    Medium

    CVE-2020-0018

    Last Modified: 21 Nov 2024

    In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lead to local disclosure of user input with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139945049

    Published: 13 Feb 2020
    4.4
    Medium

    CVE-2020-0017

    Last Modified: 21 Nov 2024

    In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-123232892

    Published: 13 Feb 2020
    7.3
    High

    CVE-2019-2200

    Last Modified: 21 Nov 2024

    In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a permission bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-67319274

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-0015

    Last Modified: 21 Nov 2024

    In onCreate of CertInstaller.java, there is a possible way to overlay the Certificate Installation dialog by a malicious application. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139017101

    Published: 13 Feb 2020
    5.5
    Medium

    CVE-2020-0014

    Last Modified: 21 Nov 2024

    It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-128674520

    Published: 13 Feb 2020
    6.1
    Medium

    CVE-2019-14652

    Last Modified: 21 Nov 2024

    explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-8962

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow was found on the D-Link DIR-842 REVC with firmware v3.13B09 HOTFIX due to the use of strcpy for LOGINPASSWORD when handling a POST request to the /MTFWU endpoint.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-8953

    Last Modified: 21 Nov 2024

    OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-8963

    Last Modified: 21 Nov 2024

    TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2020-8964

    Last Modified: 21 Nov 2024

    TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."

    Published: 13 Feb 2020
    8.7
    High

    CVE-2020-5239

    Last Modified: 21 Nov 2024

    In Mailu before version 1.7, an authenticated user can exploit a vulnerability in Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers that have open registration or untrusted users are most impacted. The master and 1.7 branches are patched on our git repository. All Docker images published on docker.io/mailu for tags 1.5, 1.6, 1.7 and master are patched. For detailed instructions about patching and securing the server afterwards, see https://github.com/Mailu/Mailu/issues/1354

    Published: 13 Feb 2020
    4.4
    Medium

    CVE-2020-1729

    Last Modified: 21 Nov 2024

    A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been applied. The largest threat from this vulnerability is a threat to data confidentiality. This is fixed in SmallRye 1.6.2

    Published: 13 Feb 2020
    3.1
    Low

    CVE-2020-1720

    Last Modified: 21 Nov 2024

    A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

    Published: 13 Feb 2020
    7.7
    High

    CVE-2020-5241

    Last Modified: 21 Nov 2024

    matestack-ui-core (RubyGem) before 0.7.4 is vulnerable to XSS/Script injection. This vulnerability is patched in version 0.7.4.

    Published: 12 Feb 2020
    5.5
    Medium

    CVE-2018-3987

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats' functionality allows a user to delete all traces of a chat either by using a time trigger or by direct request. There is a bug in this functionality which leaves behind photos taken and shared on the secret chats, even after the chats are deleted. These photos will be stored in the device and accessible to all applications installed on the Android device.

    Published: 12 Feb 2020