LiveActive security incident?Get immediate response
CVE archive

August 2020

Browse CVE records published in August 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1514 matching CVEs · Page 6 of 31.

Low · CVSS 2.8

CVE-2020-8905: Confidential Information Disclosure vulnerability in Asylo

A buffer length validation vulnerability in Asylo versions prior to 0.6.0 allows an attacker to read data they should not have access to. The 'enc_untrusted_recvfrom' function generates a return value which is deserialized by 'MessageReader', and copied into three different 'extents'. The length of the third 'extents' is controlled by the outside world, and not verified on copy, allowing the attacker to force Asylo to copy trusted memory data into an untrusted buffer of significantly small length.. We recommend updating Asylo to version 0.6.0 or later.

Published Aug 12, 2020 · Updated Sep 17, 2024

Critical · CVSS 9.4

CVE-2020-28434: Command Injection

This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.

Published Aug 2, 2022 · Updated Sep 16, 2024

High · CVSS 7.1

CVE-2020-7376: Rapid7 Metasploit Framework Relative Path Traversal in enum_osx module

The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.

Published Aug 24, 2020 · Updated Sep 16, 2024

Medium · CVSS 6.7

CVE-2020-5419: RabbitMQ arbitrary code execution using local binary planting

RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.

Published Aug 31, 2020 · Updated Sep 16, 2024

Medium · CVSS 5.7

CVE-2020-12781: Combodo iTop - CSRF

Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

Published Aug 10, 2020 · Updated Sep 16, 2024

Medium · CVSS 6.4

CVE-2020-8904: Arbitrary trusted memory overwrite vulnerability in Asylo

An arbitrary memory overwrite vulnerability in the trusted memory of Asylo exists in versions prior to 0.6.0. As the ecall_restore function fails to validate the range of the output_len pointer, an attacker can manipulate the tmp_output_len value and write to an arbitrary location in the trusted (enclave) memory. We recommend updating Asylo to version 0.6.0 or later.

Published Aug 12, 2020 · Updated Sep 16, 2024

High · CVSS 7.3

CVE-2020-7795: Command Injection

The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.

Published Aug 2, 2022 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2020-7810: HandySoft ActiveX File Download and Execution Vulnerability

hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the update process, and a remote attacker could induce a user to crafted web page, causing damage such as malicious code infection.

Published Aug 7, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7703: Prototype Pollution

All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.

Published Aug 17, 2020 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2020-4165: IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the vic...

IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174401.

Published Aug 24, 2020 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2020-9062: Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate,...

Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages between the CCDM and the host computer, allowing an attacker with physical access to internal ATM components to commit deposit forgery by intercepting and modifying messages to the host computer, such as the amount and value of currency being deposited.

Published Aug 21, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7707: Prototype Pollution

The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.

Published Aug 18, 2020 · Updated Sep 16, 2024

Medium · CVSS 6.4

CVE-2020-7029: Avaya Product System Management Interface Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of Communication Manager are 7.0.x, 7.1.x prior to 7.1.3.5 and 8.0.x. Affected versions of Messaging are 7.0.x, 7.1 and 7.1 SP1.

Published Aug 11, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.6

CVE-2020-7361: ZenTao Pro Command Injection

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.

Published Aug 6, 2020 · Updated Sep 16, 2024

High · CVSS 8

CVE-2020-10289: RVD#2401: Use of unsafe yaml load, ./src/actionlib/tools/library.py:132

Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creation of Python objects. Through this flaw in the ROS core package of actionlib, an attacker with local or remote access can make the ROS Master, execute arbitrary code in Python form. Consider yaml.safe_load() instead. Located first in actionlib/tools/library.py:132. See links for more info on the bug.

Published Aug 20, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7708: Prototype Pollution

The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.

Published Aug 18, 2020 · Updated Sep 16, 2024

Medium · CVSS 5.5

CVE-2020-15701: Unhandled exception in apport

An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an unhandled exception, resulting in a crash. Fixed in 2.20.1-0ubuntu2.24, 2.20.9-0ubuntu7.16, 2.20.11-0ubuntu27.6.

Published Aug 6, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-7702: Prototype Pollution

All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.

Published Aug 17, 2020 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2020-4706: IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validat...

IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 187194.

Published Aug 17, 2021 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2020-14522: Softing Industrial Automation OPC

Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a denial-of-service condition.

Published Aug 25, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.4

CVE-2020-28453: Command Injection

This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.

Published Aug 2, 2022 · Updated Sep 16, 2024

High · CVSS 7.1

CVE-2020-7705: Malicious Package

This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attribution fraud. Mintegral can remotely activate hooks on the UIApplication, openURL, SKStoreProductViewController, loadProductWithParameters and NSURLProtocol methods along with anti-debug and proxy detection protection. If those hooks are active MintegralAdSDK sends obfuscated data about every opened URL in an application to their servers. Note that the malicious functionality is enabled even if the SDK was not enabled to serve ads.

Published Aug 24, 2020 · Updated Sep 16, 2024

High · CVSS 8.1

CVE-2020-7710: Sandbox Escape

This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.

Published Aug 21, 2020 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2020-14510: OFF-BY-ONE ERROR CWE-193

GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root.

Published Aug 25, 2020 · Updated Sep 16, 2024