Medium · CVSS 5.5
The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device.
Published Nov 10, 2020 · Updated Sep 16, 2024
Low · CVSS 2.8
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.
Published Nov 11, 2020 · Updated Sep 16, 2024
Low · CVSS 3.3
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Nov 5, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.6
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had been used for internal testing.
Published Nov 5, 2020 · Updated Sep 16, 2024
High · CVSS 7
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 188736.
Published Nov 9, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.9
IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 174340.
Published Nov 8, 2021 · Updated Sep 16, 2024
Low · CVSS 2.7
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect permissions vulnerability within the Integrations component. This vulnerability could be abused by users with permissions to the Pages resource to delete cms pages via the REST API without authorization.
Published Nov 9, 2020 · Updated Sep 16, 2024
Medium · CVSS 4.4
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a security feature bypass that could result in dynamic library code injection by the Adobe Reader process. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Nov 5, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass.
Published Nov 15, 2021 · Updated Sep 16, 2024
Medium · CVSS 4.3
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 186280.
Published Nov 16, 2020 · Updated Sep 16, 2024
Critical · CVSS 9.3
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
Published Nov 6, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution.
Published Nov 15, 2021 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 189219.
Published Nov 3, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.
Published Nov 25, 2020 · Updated Sep 16, 2024
Low · CVSS 3.3
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.
Published Nov 11, 2020 · Updated Sep 16, 2024
Medium · CVSS 4.8
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187190.
Published Nov 16, 2020 · Updated Sep 16, 2024
High · CVSS 7.1
Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations and interact with hosts on the network. This issue affects: Bitdefender Update Server versions prior to 6.6.20.294.
Published Nov 9, 2020 · Updated Sep 16, 2024
High · CVSS 7.5
An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device. This vulnerability allows an attacker to gain privileged access to the Panorama web interface. An attacker requires some knowledge of managed firewalls to exploit this issue. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.17; PAN-OS 9.0 versions earlier than PAN-OS 9.0.11; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5.
Published Nov 12, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.6
Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to Orchestrator by introducing an HTTP HOST header set to 127.0.0.1 or localhost. Orchestrator instances that are hosted by customers –on-premise or in a public cloud provider –are affected by this vulnerability.
Published Nov 5, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.
Published Nov 16, 2021 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM QRadar Network Security 5.4.0 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174269.
Published Nov 8, 2021 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Arbitrary Decrement Privilege Escalation in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
Published Nov 15, 2021 · Updated Sep 16, 2024
High · CVSS 7.2
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.
Published Nov 12, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.3
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session. IBM X-Force ID: 186789.
Published Nov 30, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.3
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow an authenticated user to bypass security. A user with access to a snapshot could apply unauthorized additional statuses via direct rest calls. IBM X-Force ID: 181856.
Published Nov 6, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004203 may lead to arbitrary information disclosure.
Published Nov 15, 2021 · Updated Sep 16, 2024
Low · CVSS 2.7
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorized changes to inventory source data via the REST API.
Published Nov 9, 2020 · Updated Sep 16, 2024
Medium · CVSS 5.3
All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!.
Published Nov 26, 2020 · Updated Sep 16, 2024
Low · CVSS 3.3
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a use-after-free vulnerability that could result in a memory address leak. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Nov 5, 2020 · Updated Sep 16, 2024
High · CVSS 8.2
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Published Nov 7, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
Published Nov 3, 2023 · Updated Sep 12, 2024
Medium · CVSS 5.4
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.8
Visual Studio Code JSHint Extension Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.8
Raw Image Extension Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 8.5
Microsoft Exchange Server Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Medium · CVSS 5.5
Microsoft Exchange Server Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.8
Raw Image Extension Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Medium · CVSS 5.5
Microsoft Raw Image Extension Information Disclosure Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.8
Microsoft Excel Security Feature Bypass Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.8
Microsoft Excel Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.8
Microsoft Excel Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.8
Microsoft Excel Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Medium · CVSS 6.8
Microsoft Office Online Spoofing Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.8
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Medium · CVSS 5.4
Microsoft SharePoint Server Spoofing Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.5
Microsoft Browser Memory Corruption Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.5
Internet Explorer Memory Corruption Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
High · CVSS 7.5
Scripting Engine Memory Corruption Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Critical · CVSS 9.8
Windows Network File System Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Medium · CVSS 4.2
Chakra Scripting Engine Memory Corruption Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024