|
197731
|
7.5 |
HIGH
Network
|
ibm
|
datapower_gateway
|
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: …
|
NVD-CWE-noinfo
|
CVE-2020-4579
|
2024-11-21 14:32 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197732
|
4.3 |
MEDIUM
Network
|
ibm
|
business_automation_content_analyzer_on_cloud
|
IBM Business Automation Content Analyzer on Cloud 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http://…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4315
|
2024-11-21 14:32 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197733
|
7.8 |
HIGH
Local
|
installbuilder
|
installbuilder
|
InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initialization time, writable by non-admin users. While those plugins are not require…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-3979
|
2024-11-21 14:32 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197734
|
6.1 |
MEDIUM
Local
|
vmware
|
horizon_client workstation_player workstation_pro
|
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (JPEG2000 parser). A malicious actor with normal…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-3988
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197735
|
6.1 |
MEDIUM
Local
|
vmware
|
horizon_client workstation_player workstation_pro
|
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor wi…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-3987
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197736
|
6.5 |
MEDIUM
Local
|
vmware
|
horizon_client workstation_player workstation_pro
|
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerability due to an integer overflow issue in Cortado ThinPrint component. A maliciou…
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2020-3990
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197737
|
3.3 |
LOW
Local
|
vmware
|
horizon_client workstation_player workstation_pro
|
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious a…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-3989
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197738
|
6.1 |
MEDIUM
Local
|
vmware
|
horizon_client workstation_player workstation_pro
|
VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal acce…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-3986
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197739
|
6.7 |
MEDIUM
Local
|
vmware
|
fusion
|
VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. An attacker with normal user privileges may exploit this issue to trick a…
|
NVD-CWE-noinfo
|
CVE-2020-3980
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197740
|
8.2 |
HIGH
Network
|
ibm
|
maximo_for_life_sciences maximo_for_transportation control_desk maximo_for_oil_and_gas maximo_for_aviation maximo_for_utilities maximo_for_nuclear_power maximo_equipment_maintena…
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remot…
|
CWE-601
Open Redirect
|
CVE-2020-4409
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|