CVE-2020-17107: HEVC Video Extensions Remote Code Execution Vulnerability
HEVC Video Extensions Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Browse CVE records published in November 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 1371 matching CVEs · Page 9 of 28.
HEVC Video Extensions Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
HEVC Video Extensions Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
WebP Image Extensions Information Disclosure Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
HEIF Image Extensions Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Visual Studio Tampering Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Raw Image Extension Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Update Stack Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Update Orchestrator Service Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows USO Core Worker Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Update Orchestrator Service Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Delivery Optimization Information Disclosure Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Update Medic Service Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows NDIS Information Disclosure Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows GDI+ Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Win32k Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Network File System Information Disclosure Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Remote Access Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Microsoft Word Security Feature Bypass Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Microsoft Excel Remote Code Execution Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Graphics Component Information Disclosure Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows Print Spooler Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Windows WalletService Information Disclosure Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
DirectX Elevation of Privilege Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Remote Desktop Protocol Server Information Disclosure Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
Microsoft SharePoint Information Disclosure Vulnerability
Published Nov 11, 2020 · Updated Sep 10, 2024
An issue was discovered on Bell HomeHub 3000 SG48222070 devices. Remote authenticated users can retrieve the serial number via cgi/json-req - this is an information leak because the serial number is intended to prove an actor's physical access to the device.
Published Nov 17, 2023 · Updated Sep 4, 2024
An issue was discovered on Bell HomeHub 3000 SG48222070 devices. There is XSS related to the email field and the login page.
Published Nov 17, 2023 · Updated Sep 4, 2024
The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
Published Nov 1, 2021 · Updated Aug 4, 2024
The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.
Published Nov 1, 2021 · Updated Aug 4, 2024
The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog
Published Nov 1, 2021 · Updated Aug 4, 2024
Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature.
Published Nov 2, 2021 · Updated Aug 4, 2024
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH is not always available. An attacker can intercept passwords sent in cleartext and conduct a man-in-the-middle attack on the management of the appliance.
Published Nov 29, 2020 · Updated Aug 4, 2024
The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical access can unlock the password manager without knowing the master password set by the user.
Published Nov 30, 2020 · Updated Aug 4, 2024
An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. A hardcoded RSA private key (specific to V1600D4L and V1600D-MINI) is contained in the firmware images.
Published Nov 29, 2020 · Updated Aug 4, 2024
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. A hardcoded RSA private key (specific to V1600D, V1600G1, and V1600G2) is contained in the firmware images.
Published Nov 29, 2020 · Updated Aug 4, 2024
An issue was discovered in PNGOUT 2020-01-15. When compressing a crafted PNG file, it encounters an integer overflow.
Published Nov 30, 2020 · Updated Aug 4, 2024
Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker (who is inside a vehicle, or is otherwise able to send data over the CAN bus) to start and drive the vehicle with a spoofed key fob.
Published Nov 30, 2020 · Updated Aug 4, 2024
A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is misused (no limit on the number of characters to be read in the format argument).
Published Nov 30, 2020 · Updated Aug 4, 2024
Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This allows attackers to construct firmware that retrieves an unlock code from a secure enclave chip.
Published Nov 30, 2020 · Updated Aug 4, 2024
An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In some cases, this attack may consume the available database space (Denial of Service), corrupt legitimate data if files are being processed asynchronously, or deny access to legitimate uploaded files.
Published Nov 30, 2020 · Updated Aug 4, 2024
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.
Published Nov 30, 2020 · Updated Aug 4, 2024
Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a body control module (BCM) to initiate a Bluetooth wake-up action. (The full VIN is visible from outside the vehicle.)
Published Nov 30, 2020 · Updated Aug 4, 2024
The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
Published Nov 30, 2020 · Updated Aug 4, 2024
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. Command injection can occur in "upload tftp syslog" and "upload tftp configuration" in the CLI via a crafted filename.
Published Nov 29, 2020 · Updated Aug 4, 2024
An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating the firmware, the update script starts a telnetd -l /bin/sh process that does not require authentication for TELNET access.
Published Nov 29, 2020 · Updated Aug 4, 2024
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. An low-privileged (non-admin) attacker can use a hardcoded password (4ef9cea10b2362f15ba4558b1d5c081f) to create an admin user.
Published Nov 29, 2020 · Updated Aug 4, 2024
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.
Published Nov 28, 2020 · Updated Aug 4, 2024
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. It is possible to elevate the privilege of a CLI user (to full administrative access) by using the password !j@l#y$z%x6x7q8c9z) for the enable command.
Published Nov 29, 2020 · Updated Aug 4, 2024