Latest CVE Feed
-
7.8
HIGHCVE-2020-8853
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-8852
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8851
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8850
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8849
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8848
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8847
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8846
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fi... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8845
This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fi... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8844
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.... Read more
- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2020-8843
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at ingress that can be used to affect policy decisions when... Read more
Affected Products : istio- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-8841
An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.... Read more
Affected Products : testlink- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8840
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.... Read more
- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-8839
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.... Read more
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2020-8838
An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileg... Read more
Affected Products : manageengine_assetexplorer- Published: Mar. 23, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8835
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 sta... Read more
Affected Products : linux_kernel ubuntu_linux fedora a700s_firmware 8300_firmware 8700_firmware a400_firmware cloud_backup hci_management_node solidfire +37 more products- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8834
KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel spa... Read more
- Published: Apr. 09, 2020
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2020-8833
Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this can be exploited between the os.open and os.chown calls wh... Read more
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8832
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the ker... Read more
- Published: Apr. 10, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8831
Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the directory, otherwise it will simply ... Read more
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024