Show filters
436 Total Results
Displaying 1-10 of 436
Sort by:
Attacker Value
Very High
CVE-2020-3259
Disclosure Date: May 06, 2020 (last updated February 21, 2025)
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.
9
Attacker Value
High
CVE-2020-9337
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
0
Attacker Value
High
CVE-2020-15099
Disclosure Date: July 29, 2020 (last updated February 21, 2025)
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attacker manages to generate a valid cryptographic message authentication code (HMAC-SHA1) - either by using a different existing vulnerability or in case the internal encryptionKey was exposed - it is possible to retrieve arbitrary files of a TYPO3 installation. This includes the possibility to fetch typo3conf/LocalConfiguration.php, which again contains the encryptionKey as well as credentials of the database management system being used. In case a database server is directly accessible either via internet or in a shared hosting network, this allows the ability to completely retrieve, manipulate or delete database contents. This includes creating an administration user account - which can be used to trigger remote code execution by injecting custom extensions. This has been patched in versions 9.5.20 and 10.4.6.
1
Attacker Value
Unknown
CVE-2020-35710
Disclosure Date: December 25, 2020 (last updated February 22, 2025)
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client for use as a "host" value. In other words, after an attacker's web browser sent a request to the login form, it would automatically send a second request to a RASHTML5Gateway/socket.io URI with something like "host":"192.168.###.###" in the POST data.
0
Attacker Value
Unknown
CVE-2020-12518
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.
0
Attacker Value
Unknown
CVE-2019-14480
Disclosure Date: December 16, 2020 (last updated February 22, 2025)
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
0
Attacker Value
Unknown
CVE-2020-0488
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158484516
0
Attacker Value
Unknown
CVE-2020-4908
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the login dialog. This information could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2019-19283
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive information about the server's architecture. This could allow an attacker to adapt further attacks to the version in place.
0
Attacker Value
Unknown
CVE-2020-8169
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
0