Show filters
496 Total Results
Displaying 291-300 of 496
Sort by:
Attacker Value
Unknown

CVE-2020-29245

Disclosure Date: December 28, 2020 (last updated February 22, 2025)
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData.
Attacker Value
Unknown

CVE-2020-29244

Disclosure Date: December 28, 2020 (last updated February 22, 2025)
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.
Attacker Value
Unknown

CVE-2020-7548

Disclosure Date: December 01, 2020 (last updated February 22, 2025)
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.
Attacker Value
Unknown

CVE-2020-15272

Disclosure Date: October 26, 2020 (last updated February 22, 2025)
In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has been patched in version 1.0.1. If you don't use the `tag` input you are most likely safe. The `GITHUB_REF` environment variable is protected by the GitHub Actions environment so attacks from there should be impossible. If you must use the `tag` input and cannot upgrade to `> 1.0.0` make sure that the value is not controlled by another Action.
Attacker Value
Unknown

CVE-2020-7590

Disclosure Date: October 13, 2020 (last updated February 22, 2025)
A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Affected devices use a hard-coded password to protect the onboard database. This could allow an attacker to read and or modify the onboard database. Successful exploitation requires direct physical access to the device.
Attacker Value
Unknown

CVE-2020-15797

Disclosure Date: October 13, 2020 (last updated February 22, 2025)
A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Improper Access Control could allow an unauthenticated attacker to escape from the restricted environment (“kiosk mode”) and access the underlying operating system. Successful exploitation requires direct physical access to the system.
Attacker Value
Unknown

CVE-2020-15720

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
In Dogtag PKI through 10.8.3, the pki.client.PKIConnection class did not enable python-requests certificate validation. Since the verify parameter was hard-coded in all request functions, it was not possible to override the setting. As a result, tools making use of this class, such as the pki-server command, may have been vulnerable to Person-in-the-Middle attacks in certain non-localhost use cases. This is fixed in 10.9.0-b1.
Attacker Value
Unknown

CVE-2020-8316

Disclosure Date: May 14, 2020 (last updated February 21, 2025)
A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the system with elevated privileges.
Attacker Value
Unknown

CVE-2020-4384

Disclosure Date: May 05, 2020 (last updated February 21, 2025)
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 179265.
Attacker Value
Unknown

CVE-2020-8327

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to execute code with elevated privileges.