CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-4670

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper data representation. IBM X-Force ID: 171319.

    Published: 5 Feb 2020
    3.5
    Low

    CVE-2019-4616

    Last Modified: 21 Nov 2024

    IBM Cloud Automation Manager 3.2.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 168644.

    Published: 5 Feb 2020
    8.8
    High

    CVE-2019-4613

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.

    Published: 5 Feb 2020
    5.3
    Medium

    CVE-2020-8506

    Last Modified: 21 Nov 2024

    The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2019-16204

    Last Modified: 21 Nov 2024

    Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used between the switch and an external server.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2019-16203

    Last Modified: 21 Nov 2024

    Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a command line option when configuring the ESRS client.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2020-8507

    Last Modified: 21 Nov 2024

    The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2020-6969

    Last Modified: 21 Nov 2024

    It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations.

    Published: 5 Feb 2020
    5.3
    Medium

    CVE-2020-7979

    Last Modified: 21 Nov 2024

    GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2020-8114

    Last Modified: 21 Nov 2024

    GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

    Published: 5 Feb 2020
    7.5
    High

    CVE-2020-7216

    Last Modified: 21 Nov 2024

    An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.

    Published: 5 Feb 2020
    8.8
    High

    CVE-2020-5237

    Last Modified: 21 Nov 2024

    Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to BlueimpController.php; the (2) dzchunkindex, (3) dzuuid, or (4) filename parameter to DropzoneController.php; the (5) qqpartindex, (6) qqfilename, or (7) qquuid parameter to FineUploaderController.php; the (8) x-file-id or (9) x-file-name parameter to MooUploadController.php; or the (10) name or (11) chunk parameter to PluploadController.php. This is fixed in versions 1.9.3 and 2.1.5.

    Published: 5 Feb 2020
    7.8
    High

    CVE-2020-1712

    Last Modified: 9 Jun 2025

    A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.

    Published: 5 Feb 2020
    3.1
    Low

    CVE-2019-15126

    Last Modified: 21 Nov 2024

    An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2019-14559

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 5 Feb 2020
    7.8
    High

    CVE-2019-14563

    Last Modified: 21 Nov 2024

    Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 5 Feb 2020
    7.8
    High

    CVE-2019-14575

    Last Modified: 21 Nov 2024

    Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 5 Feb 2020
    6.5
    Medium

    CVE-2020-27748

    Last Modified: 21 Nov 2024

    A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.

    Published: 5 Feb 2020
    7.7
    High

    CVE-2020-5208

    Last Modified: 21 Nov 2024

    It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.

    Published: 5 Feb 2020
    5.5
    Medium

    CVE-2020-8632

    Last Modified: 21 Nov 2024

    In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

    Published: 5 Feb 2020
    2.3
    Low

    CVE-2020-8991

    Last Modified: 21 Nov 2024

    vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs. NOTE: RedHat disputes CVE-2020-8991 as not being a vulnerability since there’s no apparent route to either privilege escalation or to denial of service through the bug

    Published: 5 Feb 2020
    6.1
    Medium

    CVE-2020-1697

    Last Modified: 21 Nov 2024

    It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.

    Published: 5 Feb 2020
    5.5
    Medium

    CVE-2020-8631

    Last Modified: 21 Nov 2024

    cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2019-10786

    Last Modified: 21 Nov 2024

    network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2019-10787

    Last Modified: 21 Nov 2024

    im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.

    Published: 4 Feb 2020
    7.5
    High

    CVE-2015-2802

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability.

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2019-10788

    Last Modified: 21 Nov 2024

    im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function.

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2015-3613

    Last Modified: 21 Nov 2024

    A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page

    Published: 4 Feb 2020
    5.4
    Medium

    CVE-2015-3612

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.

    Published: 4 Feb 2020
    9.1
    Critical

    CVE-2020-6058

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which can result in the disclosure of sensitive information and denial of service. To trigger this vulnerability, an attacker needs to send a specially crafted packet to the vulnerable server.

    Published: 4 Feb 2020
    8.2
    High

    CVE-2020-6059

    Last Modified: 21 Nov 2024

    An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out of bounds memory read which can result in sensitive information disclosure and Denial Of Service. In order to trigger this vulnerability, an attacker needs to send a specially crafted packet to the vulnerable server.

    Published: 4 Feb 2020
    7.5
    High

    CVE-2020-6060

    Last Modified: 21 Nov 2024

    A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially timed sequence of SNMP connections can trigger a stack overflow, resulting in a denial of service. To trigger this vulnerability, an attacker needs to simply initiate multiple connections to the server.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2015-3611

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.

    Published: 4 Feb 2020
    5.9
    Medium

    CVE-2019-15612

    Last Modified: 21 Nov 2024

    A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.

    Published: 4 Feb 2020
    6.1
    Medium

    CVE-2019-15615

    Last Modified: 21 Nov 2024

    A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.

    Published: 4 Feb 2020
    4.8
    Medium

    CVE-2019-15619

    Last Modified: 21 Nov 2024

    Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.

    Published: 4 Feb 2020
    4.9
    Medium

    CVE-2019-15611

    Last Modified: 21 Nov 2024

    Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.

    Published: 4 Feb 2020
    4.3
    Medium

    CVE-2019-15610

    Last Modified: 21 Nov 2024

    Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.

    Published: 4 Feb 2020
    8
    High

    CVE-2019-15613

    Last Modified: 21 Nov 2024

    A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.

    Published: 4 Feb 2020
    5.4
    Medium

    CVE-2019-15614

    Last Modified: 21 Nov 2024

    Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.

    Published: 4 Feb 2020
    4.3
    Medium

    CVE-2019-15616

    Last Modified: 21 Nov 2024

    Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.

    Published: 4 Feb 2020
    5.4
    Medium

    CVE-2019-15617

    Last Modified: 21 Nov 2024

    A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.

    Published: 4 Feb 2020
    4.8
    Medium

    CVE-2019-15618

    Last Modified: 21 Nov 2024

    Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.

    Published: 4 Feb 2020
    2.7
    Low

    CVE-2019-15620

    Last Modified: 21 Nov 2024

    Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2019-15621

    Last Modified: 21 Nov 2024

    Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.

    Published: 4 Feb 2020
    2.4
    Low

    CVE-2019-15622

    Last Modified: 21 Nov 2024

    Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.

    Published: 4 Feb 2020
    5.3
    Medium

    CVE-2019-15623

    Last Modified: 21 Nov 2024

    Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

    Published: 4 Feb 2020
    4.9
    Medium

    CVE-2019-15624

    Last Modified: 21 Nov 2024

    Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.

    Published: 4 Feb 2020
    4.3
    Medium

    CVE-2020-8122

    Last Modified: 21 Nov 2024

    A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.

    Published: 4 Feb 2020
    4.3
    Medium

    CVE-2020-8117

    Last Modified: 21 Nov 2024

    Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.

    Published: 4 Feb 2020