VYPR

CVEs

101,972 total · page 1472 of 2,040

  • CVE-2020-13223HigJun 10, 2020
    risk 0.42cvss 7.5epss 0.01

    HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.

  • CVE-2020-2032HigJun 10, 2020
    risk 0.46cvss 7.0epss 0.00

    A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while performing a GlobalProtect app upgrade. This issue affects: GlobalProtect app 5.0…

  • CVE-2020-2029HigJun 10, 2020
    risk 0.47cvss 7.2epss 0.02

    An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in the PAN-OS configuration. This issue…

  • CVE-2020-2028HigJun 10, 2020
    risk 0.47cvss 7.2epss 0.02

    An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1…

  • CVE-2020-2027HigJun 10, 2020
    risk 0.47cvss 7.2epss 0.02

    A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0;…

  • CVE-2020-2026HigJun 10, 2020
    risk 0.00cvss 7.8epss 0.00

    A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This…

  • CVE-2020-0118HigJun 10, 2020
    risk 0.51cvss 7.8epss 0.00

    In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-0115HigJun 10, 2020
    risk 0.51cvss 7.8epss 0.00

    In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not…

  • CVE-2020-0114HigJun 10, 2020
    risk 0.51cvss 7.8epss 0.00

    In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User…

  • CVE-2020-7586HigJun 10, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All…

  • CVE-2020-7585HigJun 10, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All…

  • CVE-2020-7672HigJun 10, 2020
    risk 0.56cvss 8.6epss 0.02

    mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, resulting in code execution.

  • CVE-2020-7671HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.01

    goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding…

  • CVE-2020-7670HigJun 10, 2020
    risk 0.42cvss 7.5epss 0.01

    agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing. It is…

  • CVE-2020-13270HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.01

    Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

  • CVE-2020-6271HigJun 10, 2020
    risk 0.53cvss 8.2epss 0.01

    SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amounts of memory, causing the system to crash and read restricted data (files visible for technical administration users of the…

  • CVE-2020-6268HigJun 10, 2020
    risk 0.53cvss 8.1epss 0.01

    Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) does not execute the required authorization checks for an authenticated user, allowing an attacker to view and tamper…

  • CVE-2020-6264HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.01

    SAP Commerce, versions - 6.7, 1808, 1811, 1905, may allow an attacker to access information under certain conditions which would otherwise be restricted, leading to Information Disclosure.

  • CVE-2020-4436HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.03

    Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.

  • CVE-2020-4435HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.02

    Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service.…

  • CVE-2020-4434HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.03

    Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http…

  • CVE-2020-4433HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.05

    Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to…

  • CVE-2020-4432HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.03

    Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. IBM X-Force ID: 180810.

  • CVE-2020-7280HigJun 10, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic…

  • CVE-2019-3585HigJun 10, 2020
    risk 0.46cvss 7.0epss 0.00

    Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with…

  • CVE-2019-3617HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.00

    Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect protection of temporary files.

  • CVE-2020-13996HigJun 9, 2020
    risk 0.57cvss 8.8epss 0.01

    The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.

  • CVE-2020-1334HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282,…

  • CVE-2020-1324HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vulnerability'. This…

  • CVE-2020-1321HigJun 9, 2020
    risk 0.58cvss 8.8epss 0.12

    A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.

  • CVE-2020-1317HigJun 9, 2020
    risk 0.58cvss 8.8epss 0.04

    An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.

  • CVE-2020-1316HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264,…

  • CVE-2020-1314HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messages sent from TSF clients, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.

  • CVE-2020-1313HigJun 9, 2020
    risk 0.57cvss 7.8epss 0.40

    An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'.

  • CVE-2020-1312HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…

  • CVE-2020-1311HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists when Component Object Model (COM) client uses special case IIDs, aka 'Component Object Model Elevation of Privilege Vulnerability'.

  • CVE-2020-1309HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.04

    An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Microsoft Store Runtime Elevation of Privilege Vulnerability'. This…

  • CVE-2020-1307HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.04

    An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264,…

  • CVE-2020-1306HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282,…

  • CVE-2020-1305HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.

  • CVE-2020-1304HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282,…

  • CVE-2020-1302HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…

  • CVE-2020-1301HigJun 9, 2020
    risk 0.60cvss 8.8epss 0.37

    A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.

  • CVE-2020-1300HigJun 9, 2020
    risk 0.62cvss 8.8epss 0.60

    A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into…

  • CVE-2020-1299HigJun 9, 2020
    risk 0.58cvss 8.8epss 0.15

    A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution…

  • CVE-2020-1295HigJun 9, 2020
    risk 0.57cvss 8.8epss 0.03

    An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.

  • CVE-2020-1294HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1287.

  • CVE-2020-1293HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE-2020-1278.

  • CVE-2020-1292HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly restrict access to configuration settings, aka 'OpenSSH for Windows Elevation of Privilege Vulnerability'.

  • CVE-2020-1291HigJun 9, 2020
    risk 0.51cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'.