|
196581
|
2.4 |
LOW
Physics
|
lenovo
|
thinkpad_t490_\(20nx\)_firmware thinkpad_t490_\(20qx\)_firmware thinkpad_t490_\(20rx\)_firmware thinkpad_t490s_\(20nx\)_firmware thinkpad_t495_drift_firmware thinkpad_t590_\(20nx\)_fir…
|
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Re…
|
NVD-CWE-noinfo
|
CVE-2020-8341
|
2024-11-21 14:38 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196582
|
6.8 |
MEDIUM
Physics
|
lenovo
|
thinkpad_a275_firmware thinkpad_a285_firmware thinkpad_a475_firmware thinkpad_a485_firmware thinkpad_t495_drift_firmware thinkpad_t495s_jazz_firmware thinkpad_x1_carbon_\(20bx\)_fir…
|
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS ve…
|
NVD-CWE-noinfo
|
CVE-2020-8335
|
2024-11-21 14:38 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196583
|
7.8 |
HIGH
Local
|
opensuse
|
openldap2
|
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise …
|
-
|
CVE-2020-8023
|
2024-11-21 14:38 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196584
|
7.8 |
HIGH
Local
|
bitdefender
|
endpoint_security endpoint_security_tools
|
An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivileged local attacker to escalate privileges or tampe…
|
CWE-287
Improper Authentication
|
CVE-2020-8097
|
2024-11-21 14:38 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196585
|
6.5 |
MEDIUM
Network
|
bufferlist_project debian
|
bufferlist debian_linux
|
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can becom…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-8244
|
2024-11-21 14:38 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196586
|
9.8 |
CRITICAL
Network
|
ui
|
edgemax_firmware
|
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-8234
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196587
|
6.8 |
MEDIUM
Network
|
nextcloud
|
desktop
|
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
|
CWE-22
Path Traversal
|
CVE-2020-8227
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196588
|
5.4 |
MEDIUM
Network
|
nextcloud
|
desktop
|
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8189
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196589
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue aff…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-7923
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196590
|
8.8 |
HIGH
Network
|
ui opensuse
|
edgeswitch_firmware leap backports_sle
|
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to esca…
|
CWE-78
OS Command
|
CVE-2020-8233
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|