Show filters
162 Total Results
Displaying 91-100 of 162
Sort by:
Attacker Value
Unknown

CVE-2020-4865

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.
Attacker Value
Unknown

CVE-2020-4524

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182434.
Attacker Value
Unknown

CVE-2020-35686

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
The SECOMN service in Sound Research DCHU model software component modules (APO) through 2.0.9.17, delivered on HP Windows 10 computers, may allow escalation of privilege via a fake DLL. (As a resolution, Windows Update is being submitted for all affected products to update to 2.0.9.18 or later.)
Attacker Value
Unknown

CVE-2020-4733

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127.
Attacker Value
Unknown

CVE-2020-4487

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181862.
Attacker Value
Unknown

CVE-2020-4691

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186698.
Attacker Value
Unknown

CVE-2020-4697

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790.
Attacker Value
Unknown

CVE-2020-4544

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189.
Attacker Value
Unknown

CVE-2020-25187

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
Medtronic MyCareLink Smart 25000 all versions are vulnerable when an attacker who gains auth runs a debug command, which is sent to the reader causing heap overflow in the MCL Smart Reader stack. A heap overflow allows attacker to remotely execute code on the MCL Smart Reader, could lead to control of device.
Attacker Value
Unknown

CVE-2020-27252

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
Medtronic MyCareLink Smart 25000 all versions are vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.