CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-0666

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0667, CVE-2020-0735, CVE-2020-0752.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0667

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0666, CVE-2020-0735, CVE-2020-0752.

    Published: 11 Feb 2020
    8.1
    High

    CVE-2020-0665

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.

    Published: 11 Feb 2020
    4.2
    Medium

    CVE-2020-0663

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.

    Published: 11 Feb 2020
    6.8
    Medium

    CVE-2020-0661

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-0751.

    Published: 11 Feb 2020
    7.5
    High

    CVE-2020-0660

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-0662

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-0658

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0659

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0747.

    Published: 11 Feb 2020
    8
    High

    CVE-2020-0655

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2020-0657

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-0618

    Last Modified: 13 Jan 2026

    A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

    Published: 11 Feb 2020
    7.5
    High

    CVE-2020-1942

    Last Modified: 21 Nov 2024

    In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-6066

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll JPEG SOFx parser of the Accusoft ImageGear 19.5.0 library. A specially crafted JPEG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-6067

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFF tifread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted TIFF file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-6063

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-6069

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll JPEG jpegread precision parser of the Accusoft ImageGear 19.5.0 library. A specially crafted JPEG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-6064

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-6065

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the bmp_parsing function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 11 Feb 2020
    6.1
    Medium

    CVE-2011-4938

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Ariadne 2.7.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) index.php and (2) loader.php.

    Published: 11 Feb 2020
    9.8
    Critical

    CVE-2012-1124

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.

    Published: 11 Feb 2020
    6.1
    Medium

    CVE-2012-6720

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to widget/index/content_id/*.

    Published: 11 Feb 2020
    6.3
    Medium

    CVE-2012-6721

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4.2.4.

    Published: 11 Feb 2020
    —
    Unknown

    CVE-2012-2216

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6720 and CVE-2012-6721. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2012-6720 and CVE-2012-6721 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Feb 2020
    6.1
    Medium

    CVE-2012-2452

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to modules.php or (2) img_url to includes/wysiwyg/spaw/editor/plugins/imgpopup/img_popup.php.

    Published: 11 Feb 2020
    6.1
    Medium

    CVE-2012-2517

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.

    Published: 11 Feb 2020
    —
    Unknown

    CVE-2013-6499

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 11 Feb 2020
    5.4
    Medium

    CVE-2014-3826

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2013-5582

    Last Modified: 21 Nov 2024

    Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.

    Published: 11 Feb 2020
    5.4
    Medium

    CVE-2014-3827

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser action or the name parameter in an (4) edit action in the user-user module or the (5) editprofile action to modcp.php.

    Published: 11 Feb 2020
    7.3
    High

    CVE-2020-8595

    Last Modified: 21 Nov 2024

    Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.

    Published: 11 Feb 2020
    —
    Unknown

    CVE-2014-7969

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8739. Reason: This candidate is a duplicate of CVE-2014-8739. Notes: All CVE users should reference CVE-2014-8739 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Feb 2020
    9.8
    Critical

    CVE-2014-9753

    Last Modified: 21 Nov 2024

    confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.

    Published: 11 Feb 2020
    9.8
    Critical

    CVE-2013-3684

    Last Modified: 21 Nov 2024

    NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

    Published: 11 Feb 2020
    —
    Unknown

    CVE-2013-4448

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-5111. Reason: This candidate is a duplicate of CVE-2010-5111. Notes: All CVE users should reference CVE-2010-5111 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Feb 2020
    9.8
    Critical

    CVE-2013-2057

    Last Modified: 21 Nov 2024

    YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability

    Published: 11 Feb 2020
    6.1
    Medium

    CVE-2013-5988

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter.

    Published: 11 Feb 2020
    7.8
    High

    CVE-2013-3942

    Last Modified: 21 Nov 2024

    Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability

    Published: 11 Feb 2020
    6.1
    Medium

    CVE-2013-1760

    Last Modified: 21 Nov 2024

    The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities

    Published: 11 Feb 2020
    9.8
    Critical

    CVE-2013-1607

    Last Modified: 21 Nov 2024

    Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability

    Published: 11 Feb 2020
    6.1
    Medium

    CVE-2012-4519

    Last Modified: 21 Nov 2024

    Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.

    Published: 11 Feb 2020
    8.8
    High

    CVE-2020-8429

    Last Modified: 21 Nov 2024

    The Admin web application in Kinetica 7.0.9.2.20191118151947 does not properly sanitise the input for the function getLogs. This lack of sanitisation could be exploited to allow an authenticated attacker to run remote code on the underlying operating system. The logFile parameter in the getLogs function was used as a variable in a command to read log files; however, due to poor input sanitisation, it was possible to bypass a replacement and break out of the command.

    Published: 11 Feb 2020
    3.3
    Low

    CVE-2020-5831

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

    Published: 11 Feb 2020
    3.3
    Low

    CVE-2020-5830

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

    Published: 11 Feb 2020
    3.3
    Low

    CVE-2020-5829

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

    Published: 11 Feb 2020
    3.3
    Low

    CVE-2020-5828

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

    Published: 11 Feb 2020
    3.3
    Low

    CVE-2020-5827

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-5826

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

    Published: 11 Feb 2020
    —
    Unknown

    CVE-2015-2287

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A typo caused the wrong ID to be used. Notes: none

    Published: 11 Feb 2020
    5.5
    Medium

    CVE-2020-5825

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an arbitrary file write vulnerability, which is a type of issue whereby an attacker is able to overwrite existing files on the resident system without proper privileges.

    Published: 11 Feb 2020