Latest CVE Feed
-
9.8
CRITICALCVE-2020-9757
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.... Read more
Affected Products : craft_cms- Published: Mar. 04, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-9756
Patriot Viper RGB Driver 1.1 and prior exposes IOCTL and allows insufficient access control. The IOCTL Codes 0x80102050 and 0x80102054 allows a local user with low privileges to read/write 1/2/4 bytes from or to an IO port. This could be leveraged in a nu... Read more
- Published: Mar. 06, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2020-9754
NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.... Read more
- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2020-9753
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.... Read more
Affected Products : whale_browser_installer- Published: May. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9752
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe.... Read more
Affected Products : cloud_explorer- Published: Mar. 23, 2020
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2020-9751
Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade.... Read more
Affected Products : cloud_explorer- Published: Mar. 03, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9750
Adobe Animate version 20.5 (and earlier) is affected by an out-of-bounds read vulnerability, which could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .fl... Read more
- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9749
Adobe Animate version 20.5 (and earlier) is affected by an out-of-bounds read vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .fla ... Read more
- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9748
Adobe Animate version 20.5 (and earlier) is affected by a stack overflow vulnerability, which could lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .fla file ... Read more
- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9747
Adobe Animate version 20.5 (and earlier) is affected by a double free vulnerability when parsing a crafted .fla file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploi... Read more
- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9746
Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious string... Read more
- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2020-9745
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory l... Read more
- Published: Sep. 18, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2020-9744
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory l... Read more
- Published: Sep. 18, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9743
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includ... Read more
Affected Products : experience_manager- Published: Sep. 10, 2020
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2020-9742
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature. These scri... Read more
Affected Products : experience_manager- Published: Sep. 10, 2020
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2020-9741
The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may ... Read more
Affected Products : experience_manager- Published: Sep. 10, 2020
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2020-9740
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design ... Read more
Affected Products : experience_manager- Published: Sep. 10, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2020-9739
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory l... Read more
- Published: Sep. 18, 2020
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2020-9738
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts ... Read more
Affected Products : experience_manager- Published: Sep. 10, 2020
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2020-9737
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts ... Read more
Affected Products : experience_manager- Published: Sep. 10, 2020
- Modified: Nov. 21, 2024