Show filters
1,326 Total Results
Displaying 381-390 of 1,326
Sort by:
Attacker Value
Unknown

CVE-2020-27783

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
Attacker Value
Unknown

CVE-2020-25704

Disclosure Date: December 02, 2020 (last updated February 22, 2025)
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service.
Attacker Value
Unknown

CVE-2020-28579

Disclosure Date: November 18, 2020 (last updated February 22, 2025)
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.
Attacker Value
Unknown

CVE-2020-28580

Disclosure Date: November 18, 2020 (last updated February 22, 2025)
A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
Attacker Value
Unknown

CVE-2020-28581

Disclosure Date: November 18, 2020 (last updated February 22, 2025)
A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
Attacker Value
Unknown

CVE-2020-28578

Disclosure Date: November 18, 2020 (last updated February 22, 2025)
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.
Attacker Value
Unknown

CVE-2020-4592

Disclosure Date: November 17, 2020 (last updated November 28, 2024)
IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages.
Attacker Value
Unknown

CVE-2020-27694

Disclosure Date: November 09, 2020 (last updated November 28, 2024)
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 has updated a specific critical library that may vulnerable to attack.
Attacker Value
Unknown

CVE-2020-27017

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.
Attacker Value
Unknown

CVE-2020-27019

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an attacker to access a specific database and key.