|
197341
|
5.3 |
MEDIUM
Network
|
vmware
|
esxi workstation cloud_foundation fusion
|
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors cont…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-3995
|
2024-11-21 14:32 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197342
|
7.4 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate v…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-3994
|
2024-11-21 14:32 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197343
|
5.9 |
MEDIUM
Network
|
vmware
|
cloud_foundation nsx-t_data_center
|
VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious ac…
|
NVD-CWE-noinfo
|
CVE-2020-3993
|
2024-11-21 14:32 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197344
|
9.8 |
CRITICAL
Network
|
vmware
|
esxi cloud_foundation
|
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the man…
|
CWE-416
Use After Free
|
CVE-2020-3992
|
2024-11-21 14:32 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197345
|
5.8 |
MEDIUM
Network
|
vmware
|
esxi workstation cloud_foundation fusion
|
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulne…
|
CWE-125 CWE-367
Out-of-bounds Read Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-3981
|
2024-11-21 14:32 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197346
|
5.4 |
MEDIUM
Network
|
ibm
|
sterling_file_gateway sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-site scripting. This vulnerability allows users to e…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4564
|
2024-11-21 14:32 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197347
|
5.5 |
MEDIUM
Local
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale V4.2.0.0 through V4.2.3.22 and V5.0.0.0 through V5.0.5 could allow a local attacker to cause a denial of service by sending a large number of RPC requests to the mmfsd daemon which…
|
NVD-CWE-noinfo
|
CVE-2020-4491
|
2024-11-21 14:32 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197348
|
7.7 |
HIGH
Network
|
vmware
|
esxi cloud_foundation workstation workstation_player fusion
|
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vuln…
|
CWE-787 CWE-367
Out-of-bounds Write Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-3982
|
2024-11-21 14:32 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197349
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium_big_data_intelligence
|
IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 17556…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4254
|
2024-11-21 14:32 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197350
|
7.1 |
HIGH
Local
|
vmware
|
horizon_client
|
VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue ma…
|
NVD-CWE-Other
|
CVE-2020-3991
|
2024-11-21 14:32 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|