|
197961
|
5.3 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configur…
|
NVD-CWE-noinfo
|
CVE-2020-4017
|
2024-11-21 14:32 |
2020-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197962
|
5.3 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira applicatio…
|
NVD-CWE-noinfo
|
CVE-2020-4016
|
2024-11-21 14:32 |
2020-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197963
|
4.3 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
|
NVD-CWE-noinfo
|
CVE-2020-4015
|
2024-11-21 14:32 |
2020-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197964
|
4.3 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authori…
|
NVD-CWE-noinfo
|
CVE-2020-4014
|
2024-11-21 14:32 |
2020-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197965
|
5.4 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the re…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4013
|
2024-11-21 14:32 |
2020-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197966
|
3.3 |
LOW
Local
|
vmware
|
workstation fusion esxi
|
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability i…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-3959
|
2024-11-21 14:32 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197967
|
5.5 |
MEDIUM
Local
|
vmware
|
workstation fusion esxi
|
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerabi…
|
CWE-617
Reachable Assertion
|
CVE-2020-3958
|
2024-11-21 14:32 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197968
|
7.0 |
HIGH
Local
|
vmware
|
fusion horizon_client remote_console
|
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-o…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-3957
|
2024-11-21 14:32 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197969
|
6.1 |
MEDIUM
Network
|
ibm
|
business_process_manager business_automation_workflow
|
IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An a…
|
NVD-CWE-Other
|
CVE-2020-4490
|
2024-11-21 14:32 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197970
|
7.0 |
HIGH
Local
|
ibm
|
mq_for_hpe_nonstop
|
IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427.
|
NVD-CWE-noinfo
|
CVE-2020-4352
|
2024-11-21 14:32 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|