Latest CVE Feed
-
7.5
HIGHCVE-2020-8285
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire peoplesoft_enterprise_peopletools macos clustered_data_ontap mac_os_x libcurl +21 more products- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-8284
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for ... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire peoplesoft_enterprise_peopletools macos clustered_data_ontap mac_os_x sinec_infrastructure_network_services +19 more products- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-8283
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.... Read more
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-8282
A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.... Read more
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8281
A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.... Read more
Affected Products : contacts- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8280
A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.... Read more
Affected Products : contacts- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2020-8279
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.... Read more
Affected Products : social- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2020-8278
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.... Read more
Affected Products : social- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8277
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of r... Read more
- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8276
The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows. The intended behavior was to log the timestamp for incogn... Read more
Affected Products : brave- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-8275
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device ... Read more
Affected Products : secure_mail- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8274
Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the And... Read more
Affected Products : secure_mail- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-8273
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.... Read more
Affected Products : sd-wan- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8272
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8... Read more
Affected Products : sd-wan- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-8271
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8... Read more
Affected Products : sd-wan- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-8270
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342... Read more
Affected Products : virtual_apps_and_desktops- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-8269
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9... Read more
- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8268
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.... Read more
Affected Products : json8-merge-patch- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2020-8267
A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token” improperly, allowing attackers to use the API to send authenticated messages without a valid token.This ... Read more
Affected Products : unifi_protect_firmware- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2020-8265
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap objec... Read more
- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024