|
197041
|
7.8 |
HIGH
Local
|
ibm
|
i2_analysts_notebook
|
IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, a…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-4722
|
2024-11-21 14:33 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197042
|
7.8 |
HIGH
Local
|
ibm
|
i2_analysts_notebook
|
IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, a…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-4721
|
2024-11-21 14:33 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197043
|
6.5 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot…
|
CWE-22
Path Traversal
|
CVE-2020-4782
|
2024-11-21 14:33 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197044
|
7.5 |
HIGH
Network
|
ibm
|
sterling_connect\
|
IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buffer over-read. Bysending a specially crafted reques…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-4767
|
2024-11-21 14:33 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197045
|
8.6 |
HIGH
Local
|
sonicwall
|
global_vpn_client
|
SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execution in the target s…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-5145
|
2024-11-21 14:33 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197046
|
7.8 |
HIGH
Local
|
sonicwall
|
global_vpn_client
|
SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability.
|
CWE-426
Untrusted Search Path
|
CVE-2020-5144
|
2024-11-21 14:33 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197047
|
5.5 |
MEDIUM
Local
|
ibm
|
spectrum_scale elastic_storage_server
|
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on th…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-4756
|
2024-11-21 14:33 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197048
|
5.4 |
MEDIUM
Network
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4755
|
2024-11-21 14:33 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197049
|
4.3 |
MEDIUM
Network
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a us…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2020-4749
|
2024-11-21 14:33 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197050
|
6.1 |
MEDIUM
Network
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4748
|
2024-11-21 14:33 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|