|
210791
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is …
|
NVD-CWE-noinfo
|
CVE-2020-0625
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210792
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is …
|
NVD-CWE-noinfo
|
CVE-2020-0623
|
2024-11-21 13:53 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210793
|
8.8 |
HIGH
Network
|
3cx debian
|
phone_system_firmware debian_linux
|
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><sp…
|
CWE-77
Command Injection
|
CVE-2019-9972
|
2024-11-21 13:52 |
2022-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210794
|
8.8 |
HIGH
Network
|
3cx debian
|
phone_system_firmware debian_linux
|
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password. This occurs bec…
|
CWE-269
Improper Privilege Management
|
CVE-2019-9971
|
2024-11-21 13:52 |
2022-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210795
|
7.8 |
HIGH
Local
|
google
|
android
|
In deletePackageVersionedInternal of PackageManagerService.java, there is a possible way to exit Screen Pinning due to a permissions bypass. This could lead to local escalation of privilege with no a…
|
NVD-CWE-noinfo
|
CVE-2020-0025
|
2024-11-21 13:52 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210796
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction i…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-0019
|
2024-11-21 13:52 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210797
|
7.8 |
HIGH
Local
|
google
|
android
|
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-0016
|
2024-11-21 13:52 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210798
|
7.8 |
HIGH
Local
|
google
|
android
|
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no addition…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-0099
|
2024-11-21 13:52 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210799
|
7.8 |
HIGH
Local
|
google
|
android
|
In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding audio settings with no additional execution privileges needed. User interaction is…
|
CWE-862
Missing Authorization
|
CVE-2020-0089
|
2024-11-21 13:52 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210800
|
7.8 |
HIGH
Local
|
google
|
android
|
In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User …
|
CWE-20 CWE-77
Improper Input Validation Command Injection
|
CVE-2020-0130
|
2024-11-21 13:52 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|