CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2015-7508

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file.

    Published: 12 Feb 2020
    7.5
    High

    CVE-2014-6262

    Last Modified: 21 Nov 2024

    Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted third argument to the rrdtool.graph function, aka ZEN-15415, a related issue to CVE-2013-2131.

    Published: 12 Feb 2020
    9.8
    Critical

    CVE-2014-2595

    Last Modified: 21 Nov 2024

    Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2014-4968

    Last Modified: 21 Nov 2024

    The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attackers to execute arbitrary code via a crafted web site, a related issue to CVE-2012-6636.

    Published: 12 Feb 2020
    5.5
    Medium

    CVE-2020-10029

    Last Modified: 21 Nov 2024

    The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.

    Published: 12 Feb 2020
    7.5
    High

    CVE-2015-9542

    Last Modified: 21 Nov 2024

    add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.

    Published: 12 Feb 2020
    5.3
    Medium

    CVE-2020-7957

    Last Modified: 21 Nov 2024

    The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages.

    Published: 12 Feb 2020
    7.5
    High

    CVE-2020-7046

    Last Modified: 21 Nov 2024

    lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2020-2109

    Last Modified: 21 Nov 2024

    Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed methods.

    Published: 12 Feb 2020
    5.4
    Medium

    CVE-2020-2111

    Last Modified: 21 Nov 2024

    Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.

    Published: 12 Feb 2020
    5.9
    Medium

    CVE-2020-8890

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.

    Published: 11 Feb 2020
    5.9
    Medium

    CVE-2020-8891

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.

    Published: 11 Feb 2020
    8.1
    High

    CVE-2020-8892

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-0792

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, CVE-2020-0745.

    Published: 11 Feb 2020
    7.5
    High

    CVE-2020-0767

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-0759

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-0756

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles objects in memory., aka 'Windows Key Isolation Service Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0675, CVE-2020-0676, CVE-2020-0677, CVE-2020-0748, CVE-2020-0755.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0757

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Windows improperly handles Secure Socket Shell remote commands, aka 'Windows SSH Elevation of Privilege Vulnerability'.

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-0755

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles objects in memory., aka 'Windows Key Isolation Service Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0675, CVE-2020-0676, CVE-2020-0677, CVE-2020-0748, CVE-2020-0756.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0754

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0753.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0753

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0754.

    Published: 11 Feb 2020
    6
    Medium

    CVE-2020-0751

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to handle these requests., aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-0661.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0752

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0666, CVE-2020-0667, CVE-2020-0735.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0749

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0742, CVE-2020-0743, CVE-2020-0750.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0750

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0742, CVE-2020-0743, CVE-2020-0749.

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-0748

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles objects in memory., aka 'Windows Key Isolation Service Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0675, CVE-2020-0676, CVE-2020-0677, CVE-2020-0755, CVE-2020-0756.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0747

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0659.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0745

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, CVE-2020-0792.

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-0746

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0743

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0742, CVE-2020-0749, CVE-2020-0750.

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-0744

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0742

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0743, CVE-2020-0749, CVE-2020-0750.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0741

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0742, CVE-2020-0743, CVE-2020-0749, CVE-2020-0750.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0739

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the dssvc.dll handles file creation allowing for a file overwrite or creation in a secured location, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0737.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0740

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0741, CVE-2020-0742, CVE-2020-0743, CVE-2020-0749, CVE-2020-0750.

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-0736

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0737

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the tapisrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0739.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-0738

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-0734

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0681.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0735

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0666, CVE-2020-0667, CVE-2020-0752.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0733

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Malicious Software Removal Tool (MSRT) improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability'.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0732

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0709.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0731

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0691, CVE-2020-0719, CVE-2020-0720, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0724, CVE-2020-0725, CVE-2020-0726.

    Published: 11 Feb 2020
    7.1
    High

    CVE-2020-0730

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-0728

    Last Modified: 21 Nov 2024

    An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-0729

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0726

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0691, CVE-2020-0719, CVE-2020-0720, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0724, CVE-2020-0725, CVE-2020-0731.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0727

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0724

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0691, CVE-2020-0719, CVE-2020-0720, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0725, CVE-2020-0726, CVE-2020-0731.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0725

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0691, CVE-2020-0719, CVE-2020-0720, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0724, CVE-2020-0726, CVE-2020-0731.

    Published: 11 Feb 2020