| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-3722 | Hig | 0.42 | 7.5 | 0.01 | Feb 17, 2020 | A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c. | ||
| CVE-2020-1692 | Hig | 0.53 | 8.1 | 0.01 | Feb 17, 2020 | Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course. | ||
| CVE-2020-8795 | Hig | 0.49 | 7.5 | 0.01 | Feb 17, 2020 | In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users. | ||
| CVE-2020-9005 | Hig | 0.51 | 7.8 | 0.02 | Feb 17, 2020 | meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled. | ||
| CVE-2020-9034 | Hig | 0.49 | 7.5 | 0.01 | Feb 17, 2020 | Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users. | ||
| CVE-2019-20456 | Hig | 0.51 | 7.8 | 0.01 | Feb 16, 2020 | Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking. | ||
| CVE-2020-8997 | Hig | 0.57 | 8.8 | 0.01 | Feb 16, 2020 | Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not present in the FreeStyle Libre 14-day in the U.S (announced in August 2018) and… | ||
| CVE-2020-6068 | Hig | 0.57 | 8.8 | 0.04 | Feb 14, 2020 | An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG pngread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed… | ||
| CVE-2019-5187 | Hig | 0.57 | 8.8 | 0.04 | Feb 14, 2020 | An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted TIFF file file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to… | ||
| CVE-2019-13967 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2020 | iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI.… | ||
| CVE-2020-8843 | Hig | 0.48 | 7.4 | 0.01 | Feb 14, 2020 | An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at ingress that can be used to affect policy decisions when Mixer policy… | ||
| CVE-2020-8858 | Hig | 0.58 | 8.8 | 0.07 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability. The specific flaw exists within the DestIP parameter within MainPing.asp. The… | ||
| CVE-2020-8857 | Hig | 0.51 | 7.8 | 0.06 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8856 | Hig | 0.52 | 7.8 | 0.20 | Feb 14, 2020 | This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8855 | Hig | 0.51 | 7.8 | 0.06 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.2947. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8854 | Hig | 0.51 | 7.8 | 0.06 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8853 | Hig | 0.51 | 7.8 | 0.06 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8851 | Hig | 0.51 | 7.8 | 0.06 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8850 | Hig | 0.51 | 7.8 | 0.06 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8849 | Hig | 0.51 | 7.8 | 0.06 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8848 | Hig | 0.51 | 7.8 | 0.06 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8847 | Hig | 0.51 | 7.8 | 0.06 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8846 | Hig | 0.52 | 7.8 | 0.20 | Feb 14, 2020 | This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8845 | Hig | 0.52 | 7.8 | 0.19 | Feb 14, 2020 | This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8844 | Hig | 0.53 | 7.8 | 0.24 | Feb 14, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw… | ||
| CVE-2020-8611 | Hig | 0.57 | 8.8 | 0.01 | Feb 14, 2020 | In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending… | ||
| CVE-2019-11215 | Hig | 0.53 | 8.1 | 0.01 | Feb 14, 2020 | In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload. Many conditions can place the configuration file into a writable state: during… | ||
| CVE-2019-6193 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2020 | An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes. | ||
| CVE-2019-20045 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2020 | The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. Specially crafted malicious packets could cause disconnection of active authentic connections or reboot of device. This is a different issue than… | ||
| CVE-2019-19879 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2020 | HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2. | ||
| CVE-2019-20454 | Hig | 0.42 | 7.5 | 0.02 | Feb 14, 2020 | An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash… | ||
| CVE-2013-5687 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2020 | RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure. | ||
| CVE-2013-6360 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2020 | TRENDnet TS-S402 has a backdoor to enable TELNET. | ||
| CVE-2013-6277 | Hig | 0.49 | 7.5 | 0.02 | Feb 13, 2020 | QNAP VioCard 300 has hardcoded RSA private keys. | ||
| CVE-2013-1634 | Hig | 0.49 | 7.5 | 0.02 | Feb 13, 2020 | A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller devices through 2013-02-06 where the device can be brought into a non-processing state when parsing 32 hex, 33 hex, or 34 hex byte values at the 0x47f offset.… | ||
| CVE-2015-6589 | Hig | 0.54 | 8.8 | 0.14 | Feb 13, 2020 | Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient… | ||
| CVE-2015-3309 | Hig | 0.42 | 7.5 | 0.02 | Feb 13, 2020 | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE: This vulnerability is… | ||
| CVE-2014-3208 | Hig | 0.49 | 7.5 | 0.02 | Feb 13, 2020 | A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery), | ||
| CVE-2012-6091 | Hig | 0.49 | 7.5 | 0.02 | Feb 13, 2020 | Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability. | ||
| CVE-2020-0564 | Hig | 0.51 | 7.8 | 0.00 | Feb 13, 2020 | Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2020-0563 | Hig | 0.51 | 7.8 | 0.00 | Feb 13, 2020 | Improper permissions in the installer for Intel(R) MPSS before version 3.8.6 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2020-0562 | Hig | 0.51 | 7.8 | 0.00 | Feb 13, 2020 | Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2020-0561 | Hig | 0.51 | 7.8 | 0.00 | Feb 13, 2020 | Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2012-5623 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2020 | Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords. | ||
| CVE-2020-0560 | Hig | 0.51 | 7.8 | 0.00 | Feb 13, 2020 | Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2020-8801 | Hig | 0.47 | 7.2 | 0.03 | Feb 13, 2020 | SuiteCRM through 7.11.11 allows PHAR Deserialization. | ||
| CVE-2020-8800 | Hig | 0.57 | 8.8 | 0.03 | Feb 13, 2020 | SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection. | ||
| CVE-2020-3759 | Hig | 0.49 | 7.5 | 0.04 | Feb 13, 2020 | Adobe Digital Editions versions 4.5.10 and below have a buffer errors vulnerability. Successful exploitation could lead to information disclosure. | ||
| CVE-2020-3757 | Hig | 0.58 | 8.8 | 0.10 | Feb 13, 2020 | Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2020-3756 | Hig | 0.49 | 7.5 | 0.02 | Feb 13, 2020 | Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to memory leak . |
- risk 0.42cvss 7.5epss 0.01
A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
- risk 0.53cvss 8.1epss 0.01
Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.
- risk 0.49cvss 7.5epss 0.01
In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.
- risk 0.51cvss 7.8epss 0.02
meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled.
- risk 0.49cvss 7.5epss 0.01
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.
- risk 0.51cvss 7.8epss 0.01
Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.
- risk 0.57cvss 8.8epss 0.01
Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not present in the FreeStyle Libre 14-day in the U.S (announced in August 2018) and…
- risk 0.57cvss 8.8epss 0.04
An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG pngread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed…
- risk 0.57cvss 8.8epss 0.04
An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted TIFF file file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to…
- risk 0.49cvss 7.5epss 0.01
iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI.…
- risk 0.48cvss 7.4epss 0.01
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at ingress that can be used to affect policy decisions when Mixer policy…
- risk 0.58cvss 8.8epss 0.07
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability. The specific flaw exists within the DestIP parameter within MainPing.asp. The…
- risk 0.51cvss 7.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.52cvss 7.8epss 0.20
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.51cvss 7.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.2947. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.51cvss 7.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.51cvss 7.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.51cvss 7.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.51cvss 7.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.51cvss 7.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.51cvss 7.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.51cvss 7.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.52cvss 7.8epss 0.20
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.52cvss 7.8epss 0.19
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.53cvss 7.8epss 0.24
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…
- risk 0.57cvss 8.8epss 0.01
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending…
- risk 0.53cvss 8.1epss 0.01
In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload. Many conditions can place the configuration file into a writable state: during…
- risk 0.49cvss 7.5epss 0.01
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.
- risk 0.49cvss 7.5epss 0.01
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. Specially crafted malicious packets could cause disconnection of active authentic connections or reboot of device. This is a different issue than…
- risk 0.49cvss 7.5epss 0.01
HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2.
- risk 0.42cvss 7.5epss 0.02
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash…
- risk 0.49cvss 7.5epss 0.01
RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
- risk 0.49cvss 7.5epss 0.01
TRENDnet TS-S402 has a backdoor to enable TELNET.
- risk 0.49cvss 7.5epss 0.02
QNAP VioCard 300 has hardcoded RSA private keys.
- risk 0.49cvss 7.5epss 0.02
A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller devices through 2013-02-06 where the device can be brought into a non-processing state when parsing 32 hex, 33 hex, or 34 hex byte values at the 0x47f offset.…
- risk 0.54cvss 8.8epss 0.14
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient…
- risk 0.42cvss 7.5epss 0.02
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE: This vulnerability is…
- risk 0.49cvss 7.5epss 0.02
A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery),
- risk 0.49cvss 7.5epss 0.02
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
- risk 0.51cvss 7.8epss 0.00
Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Improper permissions in the installer for Intel(R) MPSS before version 3.8.6 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.49cvss 7.5epss 0.01
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.
- risk 0.51cvss 7.8epss 0.00
Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.47cvss 7.2epss 0.03
SuiteCRM through 7.11.11 allows PHAR Deserialization.
- risk 0.57cvss 8.8epss 0.03
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
- risk 0.49cvss 7.5epss 0.04
Adobe Digital Editions versions 4.5.10 and below have a buffer errors vulnerability. Successful exploitation could lead to information disclosure.
- risk 0.58cvss 8.8epss 0.10
Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.49cvss 7.5epss 0.02
Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to memory leak .