Show filters
461 Total Results
Displaying 161-170 of 461
Sort by:
Attacker Value
Unknown
CVE-2020-7029
Disclosure Date: August 11, 2020 (last updated February 21, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of Communication Manager are 7.0.x, 7.1.x prior to 7.1.3.5 and 8.0.x. Affected versions of Messaging are 7.0.x, 7.1 and 7.1 SP1.
0
Attacker Value
Unknown
CVE-2019-7005
Disclosure Date: August 07, 2020 (last updated February 21, 2025)
A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 through 11.0.4.2.
0
Attacker Value
Unknown
CVE-2020-14063
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows unauthenticated remote attackers to inject arbitrary JavaScript via the tccj-content parameter. This is displayed in the page footer of every front-end page and executed in the browser of visitors.
0
Attacker Value
Unknown
CVE-2020-13657
Disclosure Date: June 29, 2020 (last updated November 28, 2024)
An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links. The vulnerability allows local users to take control of arbitrary files.
0
Attacker Value
Unknown
CVE-2020-7030
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3.
0
Attacker Value
Unknown
CVE-2020-11766
Disclosure Date: May 19, 2020 (last updated February 21, 2025)
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
0
Attacker Value
Unknown
CVE-2020-11050
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
0
Attacker Value
Unknown
CVE-2020-10868
Disclosure Date: April 01, 2020 (last updated November 27, 2024)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to launch the Repair App RPC call from a Low Integrity process.
0
Attacker Value
Unknown
CVE-2020-10867
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled.
0
Attacker Value
Unknown
CVE-2020-10865
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary changes to the Components section of the Stats.ini file via RPC from a Low Integrity process.
0