CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-11653

    Last Modified: 21 Nov 2024

    An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6381

    Last Modified: 21 Nov 2024

    Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6385

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6387

    Last Modified: 21 Nov 2024

    Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.

    Published: 4 Feb 2020
    4.3
    Medium

    CVE-2020-6391

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6393

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6399

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6400

    Last Modified: 21 Nov 2024

    Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6401

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6402

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6406

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6410

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigation in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to confuse the user via a crafted domain name.

    Published: 4 Feb 2020
    5.4
    Medium

    CVE-2020-6411

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 4 Feb 2020
    5.4
    Medium

    CVE-2020-6412

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6413

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML page.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6414

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 4 Feb 2020
    7.8
    High

    CVE-2020-6417

    Last Modified: 21 Nov 2024

    Inappropriate implementation in installer in Google Chrome prior to 80.0.3987.87 allowed a local attacker to execute arbitrary code via a crafted registry entry.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6499

    Last Modified: 21 Nov 2024

    Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppCache security restrictions via a crafted HTML page.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6500

    Last Modified: 21 Nov 2024

    Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6501

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 4 Feb 2020
    7.5
    High

    CVE-2020-7062

    Last Modified: 21 Nov 2024

    In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.

    Published: 4 Feb 2020
    7.8
    High

    CVE-2020-7221

    Last Modified: 21 Nov 2024

    mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6390

    Last Modified: 21 Nov 2024

    Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Feb 2020
    5.4
    Medium

    CVE-2020-6394

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6397

    Last Modified: 21 Nov 2024

    Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 4 Feb 2020
    4.3
    Medium

    CVE-2020-6403

    Last Modified: 21 Nov 2024

    Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6415

    Last Modified: 21 Nov 2024

    Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6502

    Last Modified: 21 Nov 2024

    Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 4 Feb 2020
    7.9
    High

    CVE-2019-9502

    Last Modified: 21 Nov 2024

    The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

    Published: 3 Feb 2020
    7.9
    High

    CVE-2019-9501

    Last Modified: 21 Nov 2024

    The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

    Published: 3 Feb 2020
    9.8
    Critical

    CVE-2020-8591

    Last Modified: 21 Nov 2024

    eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.

    Published: 3 Feb 2020
    9.8
    Critical

    CVE-2020-8592

    Last Modified: 21 Nov 2024

    eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).

    Published: 3 Feb 2020
    6.3
    Medium

    CVE-2019-18567

    Last Modified: 21 Nov 2024

    Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denial of service.

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2016-1000103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 3 Feb 2020
    7.5
    High

    CVE-2013-2674

    Last Modified: 21 Nov 2024

    Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer headers.

    Published: 3 Feb 2020
    6.1
    Medium

    CVE-2019-20174

    Last Modified: 21 Nov 2024

    Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.

    Published: 3 Feb 2020
    7.5
    High

    CVE-2016-4676

    Last Modified: 21 Nov 2024

    A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.

    Published: 3 Feb 2020
    6.8
    Medium

    CVE-2013-2673

    Last Modified: 21 Nov 2024

    Brother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate attackers to gain unauthorized access.

    Published: 3 Feb 2020
    6.5
    Medium

    CVE-2020-5182

    Last Modified: 21 Nov 2024

    The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar attributes such as noreferrer), the tabnabbing may occur. To reproduce the bug, create a business with a website link that contains JavaScript to exploit the window.opener property (for example, by setting window.opener.location).

    Published: 3 Feb 2020
    5.5
    Medium

    CVE-2020-4224

    Last Modified: 21 Nov 2024

    IBM StoredIQ 7.6.0.17 through 7.6.0.20 could disclose sensitive information to a local user due to data in certain directories not being encrypted when it contained symbolic links. IBM X-Force ID: 175133.

    Published: 3 Feb 2020
    6.1
    Medium

    CVE-2020-8549

    Last Modified: 21 Nov 2024

    Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.

    Published: 3 Feb 2020
    7.5
    High

    CVE-2013-2672

    Last Modified: 21 Nov 2024

    Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.

    Published: 3 Feb 2020
    7.5
    High

    CVE-2013-2646

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.

    Published: 3 Feb 2020
    6.1
    Medium

    CVE-2020-8548

    Last Modified: 21 Nov 2024

    massCode 1.0.0-alpha.6 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).

    Published: 3 Feb 2020
    7.5
    High

    CVE-2019-16893

    Last Modified: 21 Nov 2024

    The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi request.

    Published: 3 Feb 2020
    9.8
    Critical

    CVE-2020-8547

    Last Modified: 21 Nov 2024

    phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

    Published: 3 Feb 2020
    7.5
    High

    CVE-2020-8545

    Last Modified: 21 Nov 2024

    Global.py in AIL framework 2.8 allows path traversal.

    Published: 3 Feb 2020
    9.8
    Critical

    CVE-2020-8510

    Last Modified: 21 Nov 2024

    An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11267

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11264

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020