Show filters
326 Total Results
Displaying 241-250 of 326
Sort by:
Attacker Value
Unknown

CVE-2020-4097

Disclosure Date: November 05, 2020 (last updated February 22, 2025)
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client.
Attacker Value
Unknown

CVE-2020-14240

Disclosure Date: November 05, 2020 (last updated February 22, 2025)
HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
Attacker Value
Unknown

CVE-2020-27402

Disclosure Date: November 05, 2020 (last updated November 28, 2024)
The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su binary via a serial port (UART) connection or using adb.
Attacker Value
Unknown

CVE-2019-4325

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
Attacker Value
Unknown

CVE-2019-4326

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
Attacker Value
Unknown

CVE-2020-14223

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
Attacker Value
Unknown

CVE-2020-25573

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
An issue was discovered in the linked-hash-map crate before 0.5.3 for Rust. It creates an uninitialized NonNull pointer, which violates a non-null constraint.
Attacker Value
Unknown

CVE-2020-14292

Disclosure Date: September 09, 2020 (last updated November 28, 2024)
In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public Bluetooth address of the victim's phone without authorisation, bypassing the Bluetooth address randomisation protection in the user's phone.
Attacker Value
Unknown

CVE-2020-4104

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080855&sys_kb_id=971d99ed1b8ed01c086dcbfc0a4bcb6a.
Attacker Value
Unknown

CVE-2019-4090

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."