LiveActive security incident?Get immediate response
CVE archive

June 2020

Browse CVE records published in June 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1976 matching CVEs · Page 10 of 40.

Unknown · CVSS Not scored

CVE-2020-35503: A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in ve...

A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Published Jun 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-35514: An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift.

An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file and attempt to add their own node to the OpenShift cluster. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects versions before openshift4/ose-machine-config-operator v4.7.0-202105111858.p0.

Published Jun 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-35452: mod_auth_digest possible stack overflow by one nul byte

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow

Published Jun 10, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-35510: A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001.

A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB server by writing a sequence of bytes corresponding to the expected messages of a successful EJB client request, but omitting the ACK messages, or just tamper with jboss-remoting code, deleting the lines that send the ACK message from the EJB client code resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Published Jun 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-28713: Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allow...

Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote users to send push notification events via an exposed PNS server. A remote attacker can passively record push notification events which are sent over an insecure web request. The web service does not authenticate requests, and allows attackers to send an indefinite amount of motion or doorbell events to a user's mobile application by either replaying or deliberately crafting false events.

Published Jun 8, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27748: A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer.

A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.

Published Jun 1, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27383: Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can b...

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which grants the (F) Flag aka "Full Control"

Published Jun 9, 2021 · Updated Aug 4, 2024

Critical · CVSS 9.3

CVE-2020-27352: When generating the systemd service units for the docker snap (and other similar snaps), snapd does not spe...

When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.

Published Jun 21, 2024 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27384: The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerabilit...

The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full Control) for 'Everyone' group, making the entire directory 'Guild Wars 2' and its files and sub-dirs world-writable.

Published Jun 9, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-26877: ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is suscep...

ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to the redirect URI submitted with the authorization request, without checking whether the redirect URI is registered by the client who initiated the request. This allows an attacker to craft a request with a manipulated redirect URI (redirect_uri parameter), which is under the attacker's control, and consequently obtain the leaked authorization code when the server redirects the client to the manipulated redirect URI with an authorization code. NOTE: this is similar to CVE-2019-3778.

Published Jun 29, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-26885: An issue was discovered in 2sic 2sxc before 11.22.

An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an attacker to craft a malicious URL that executes a JavaScript payload in a victim's browser.

Published Jun 7, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-26516: A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4.

A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.

Published Jun 8, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-26517: A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4.

A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a project (Authn users), using the users import functionality (Admin only), and changing the login text in the application configuration (Admin only).

Published Jun 8, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-26515: An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4.

An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.

Published Jun 8, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25754: An issue was discovered on Enphase Envoy R3.x and D4.x devices.

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password derived from the MD5 hash of the username and serial number. The serial number can be retrieved by an unauthenticated user at /info.xml. Attempts to change the user password via passwd or other tools have no effect.

Published Jun 16, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25817: SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser.

SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitted data in custom project code, it can lead to vulnerabilities such as XSS on HTML output rendered through this custom code. This is now mitigated by disabling external entities during parsing. (The correct CVE ID year is 2020 [CVE-2020-25817, not CVE-2021-25817]).

Published Jun 8, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25752: An issue was discovered on Enphase Envoy R3.x and D4.x devices.

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passwords for these accounts are hardcoded values derived from the MD5 hash of the username and serial number mixed with some static strings. The serial number can be retrieved by an unauthenticated user at /info.xml. These passwords can be easily calculated by an attacker; users are unable to change these passwords.

Published Jun 16, 2021 · Updated Aug 4, 2024