LiveActive security incident?Get immediate response
CVE archive

November 2020

Browse CVE records published in November 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1371 matching CVEs · Page 17 of 28.

High · CVSS 7.5

CVE-2020-25661: A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementa...

A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. This flaw allows a remote attacker in an adjacent range to crash the system, causing a denial of service or potentially executing arbitrary code on the system by sending a specially crafted L2CAP packet. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Published Nov 5, 2020 · Updated Aug 4, 2024

Medium · CVSS 5.7

CVE-2020-25655: An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users withou...

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.

Published Nov 9, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25653: A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections.

A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from the host. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

Published Nov 26, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25650: A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the vi...

A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.

Published Nov 25, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25652: A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can...

A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user could use this flaw to prevent legitimate agents from connecting to the spice-vdagentd daemon, resulting in a denial of service. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and prior.

Published Nov 26, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25651: A flaw was found in the SPICE file transfer protocol.

A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.

Published Nov 26, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25165: BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and...

BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnerable to a network session authentication vulnerability within the authentication process between specified versions of the BD Alaris PC Unit and the BD Alaris Systems Manager. If exploited, an attacker could perform a denial-of-service attack on the BD Alaris PC Unit by modifying the configuration headers of data in transit. A denial-of-service attack could lead to a drop in the wireless capability of the BD Alaris PC Unit, resulting in manual operation of the PC Unit.

Published Nov 13, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-24719: Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack.

Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are cases where the magic cookie is included in the content of the logs. An attacker can use the cookie to attach to an Erlang node and run OS level commands on the system running the Erlang node. Affects version: 6.5.1. Fix version: 6.6.0.

Published Nov 12, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-24384: A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Co...

A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACOS versions 3.2.x (including and after 3.2.2), 4.x, and 5.1.x are affected. aGalaxy versions 3.0.x, 3.2.x, and 5.0.x are affected.

Published Nov 10, 2020 · Updated Aug 4, 2024