|
211141
|
9.8 |
CRITICAL
Network
|
solarwinds
|
orion_platform
|
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authenticatio…
|
CWE-287
Improper Authentication
|
CVE-2020-10148
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211142
|
7.8 |
HIGH
Local
|
macrium
|
reflect
|
Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivilege…
|
CWE-665
Improper Initialization
|
CVE-2020-10143
|
2024-11-21 13:54 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211143
|
5.4 |
MEDIUM
Network
|
microsoft
|
teams
|
The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as aut…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10146
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211144
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x tvos iphone_os watchos ipados
|
An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted au…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10017
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211145
|
7.8 |
HIGH
Local
|
apple
|
tvos iphone_os watchos ipados mac_os_x macos
|
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. An application may be able to ex…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10016
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211146
|
6.3 |
MEDIUM
Local
|
apple
|
macos mac_os_x
|
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to break out of its sa…
|
CWE-22
Path Traversal
|
CVE-2020-10014
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211147
|
7.8 |
HIGH
Local
|
apple
|
iphone_os tvos ipados mac_os_x
|
A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.
|
NVD-CWE-noinfo
|
CVE-2020-10013
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211148
|
6.1 |
MEDIUM
Network
|
apple
|
macos mac_os_x
|
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.0.1. Processing a maliciously crafted document may lead to a cross site scripting attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10012
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211149
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x tvos iphone_os ipados
|
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-10011
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211150
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x tvos iphone_os watchos ipados
|
A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may be able to elevate th…
|
CWE-22
Path Traversal
|
CVE-2020-10010
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|