Medium · CVSS 4.3
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM credentials to be disclosed if the user is convinced to visit a malicious web site, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to be included in the malicious web site. Impact is limited to the normal access restrictions of the user visiting the malicious web site, and subject to the user being logged into AMM, being able to connect to both AMM and the malicious web site while the web browser is open, and using a web browser that does not inherently protect against this class of attack. The JavaScript code is not executed on AMM itself.
Published Sep 15, 2020 · Updated Sep 16, 2024
High · CVSS 7.1
IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 184930.
Published Sep 22, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.4
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
Published Sep 24, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
All versions of package gedi are vulnerable to Prototype Pollution via the set function.
Published Sep 1, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
Published Sep 10, 2020 · Updated Sep 16, 2024
High · CVSS 7.5
This affects all versions of package github.com/u-root/u-root/pkg/tarutil. It is vulnerable to both leading and non-leading relative path traversal attacks in tar file extraction.
Published Sep 1, 2020 · Updated Sep 16, 2024
High · CVSS 7.5
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.
Published Sep 10, 2020 · Updated Sep 16, 2024
High · CVSS 7.5
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.
Published Sep 21, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.8
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack.
Published Sep 16, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.
Published Sep 1, 2020 · Updated Sep 16, 2024
High · CVSS 7.2
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions earlier than 9.1.4; PAN-OS 10.0 versions earlier than 10.0.1.
Published Sep 9, 2020 · Updated Sep 16, 2024
Critical · CVSS 9
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design Importer. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
Published Sep 10, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183314.
Published Sep 2, 2020 · Updated Sep 16, 2024
High · CVSS 8.8
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 182396.
Published Sep 15, 2020 · Updated Sep 16, 2024
High · CVSS 8
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 Administrative Console could allow an authenticated attacker to upload arbitrary files which could be execute arbitrary code on the vulnerable server. This vulnerability is due to an incomplete fix for CVE-2020-4470. IBM X-Force ID: 187188.
Published Sep 15, 2020 · Updated Sep 16, 2024
High · CVSS 8.2
All versions of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
Published Sep 22, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.9
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184925.
Published Sep 22, 2020 · Updated Sep 16, 2024
Medium · CVSS 4.3
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to obtain sensitive information using a specially crafted HTTP request. IBM X-Force ID: 184924.
Published Sep 22, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.8
The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.
Published Sep 4, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.
Published Sep 21, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.4
Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attackers to execute arbitrary code and steal cookies via a crafted script
Published Sep 12, 2024 · Updated Sep 12, 2024
Unknown · CVSS Not scored
A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.'
Published Sep 9, 2020 · Updated Sep 9, 2024
Medium · CVSS 5.3
A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of the component Backtracking. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.5.1 is able to address this issue. The identifier of the patch is e5a085afe6abfaea1d1a78f54c45af9ef43ca1f9. It is recommended to upgrade the affected component.
Published Sep 2, 2024 · Updated Sep 3, 2024
Unknown · CVSS Not scored
Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart.
Published Sep 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot.
Published Sep 16, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
Published Sep 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decoders\dng.cpp) when reading data from the image file.
Published Sep 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.
Published Sep 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file.
Published Sep 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 files.
Published Sep 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
Published Sep 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.
Published Sep 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when processing srf files.
Published Sep 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read the file contents from files that the running ExpertPDF process has access to read.
Published Sep 15, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
Published Sep 2, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing a maliciously crafted font file may lead to arbitrary code execution.
Published Sep 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
Published Sep 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
Published Sep 13, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app.
Published Sep 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability was found in the Linux kernel, where accessing a deallocated instance in printer_ioctl() printer_ioctl() tries to access of a printer_dev instance. However, use-after-free arises because it had been freed by gprinter_free().
Published Sep 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function.
Published Sep 8, 2021 · Updated Aug 4, 2024
High · CVSS 7.5
ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.
Published Sep 20, 2021 · Updated Aug 4, 2024
Medium · CVSS 5.9
systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix.
Published Sep 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
Published Sep 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
Published Sep 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.
Published Sep 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
Published Sep 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
Published Sep 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.
Published Sep 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document.
Published Sep 29, 2020 · Updated Aug 4, 2024