|
197001
|
3.3 |
LOW
Local
|
vmware
|
horizon_client workstation_player workstation_pro
|
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious a…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-3989
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197002
|
6.1 |
MEDIUM
Local
|
vmware
|
horizon_client workstation_player workstation_pro
|
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal acce…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-3986
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197003
|
6.7 |
MEDIUM
Local
|
vmware
|
fusion
|
VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. An attacker with normal user privileges may exploit this issue to trick a…
|
NVD-CWE-noinfo
|
CVE-2020-3980
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197004
|
8.2 |
HIGH
Network
|
ibm
|
maximo_for_life_sciences maximo_for_transportation control_desk maximo_for_oil_and_gas maximo_for_aviation maximo_for_utilities maximo_for_nuclear_power maximo_equipment_maintena…
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remot…
|
CWE-601
Open Redirect
|
CVE-2020-4409
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197005
|
5.4 |
MEDIUM
Network
|
ibm
|
business_process_manager business_automation_workflow
|
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4530
|
2024-11-21 14:32 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197006
|
4.3 |
MEDIUM
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the we…
|
CWE-352
Origin Validation Error
|
CVE-2020-4526
|
2024-11-21 14:32 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197007
|
8.8 |
HIGH
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-craf…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-4521
|
2024-11-21 14:32 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197008
|
3.3 |
LOW
Local
|
ibm
|
tivoli_business_service_manager
|
IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4344
|
2024-11-21 14:32 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197009
|
5.4 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4578
|
2024-11-21 14:32 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197010
|
5.4 |
MEDIUM
Network
|
ibm
|
business_automation_workflow business_process_manager
|
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4516
|
2024-11-21 14:32 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|